CVE-2014-4929: Path Traversal
Directory traversal vulnerability in the routing component in ownCloud Server before 5.0.17 and 6.0.x before 6.0.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in a filename, related to index.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4929?
CVE-2014-4929 is considered to have a medium severity due to its potential for directory traversal attacks.
How do I fix CVE-2014-4929?
To fix CVE-2014-4929, upgrade to ownCloud Server version 5.0.17 or 6.0.4 and above.
What kind of vulnerability is CVE-2014-4929?
CVE-2014-4929 is a directory traversal vulnerability that allows remote attackers to include and execute arbitrary local files.
Which versions of ownCloud are affected by CVE-2014-4929?
CVE-2014-4929 affects ownCloud Server versions prior to 5.0.17 and 6.0.x before 6.0.4.
What is the potential impact of CVE-2014-4929?
The potential impact of CVE-2014-4929 includes unauthorized access to sensitive files or execution of arbitrary code on the server.