CVE-2015-4715: Medium severity owncloud vulnerability
The fetch function in OAuth/Curl.php in Dropbox-PHP, as used in ownCloud Server before 6.0.8, 7.x before 7.0.6, and 8.x before 8.0.4 when an external Dropbox storage has been mounted, allows remote administrators of Dropbox.com to read arbitrary files via an @ (at sign) character in unspecified POST values.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2015-4715?
CVE-2015-4715 is a vulnerability in ownCloud Server that allows remote administrators of Dropbox.com to read arbitrary files.
What is the severity of CVE-2015-4715?
CVE-2015-4715 has a severity level of medium.
What versions of ownCloud Server are affected by CVE-2015-4715?
ownCloud Server before version 6.0.8, version 7.x before 7.0.6, and version 8.x before 8.0.4 are affected by CVE-2015-4715.
How can remote administrators of Dropbox.com exploit CVE-2015-4715?
Remote administrators of Dropbox.com can exploit CVE-2015-4715 by using an @ (at sign) character in unspecified POST requests.
Where can I find more information about CVE-2015-4715?
You can find more information about CVE-2015-4715 at the following references: [http://www.securityfocus.com/bid/76158](http://www.securityfocus.com/bid/76158), [https://github.com/owncloud/core/commit/bf0f1a50926a75a26a42a3da4d62e84a489ee77a](https://github.com/owncloud/core/commit/bf0f1a50926a75a26a42a3da4d62e84a489ee77a), [https://owncloud.org/security/advisories/mounted-dropbox-storage-allows-dropbox-com-access-file/](https://owncloud.org/security/advisories/mounted-dropbox-storage-allows-dropbox-com-access-file/)