peter bassill · operator
$ cve CVE-2014-2044 JSON

CVE-2014-2044 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 12.4% (pctl 96)

Patch early

A public exploit exists.

Description

Incomplete blacklist vulnerability in ajax/upload.php in ownCloud before 5.0, when running on Windows, allows remote authenticated users to bypass intended access restrictions, upload files with arbitrary names, and execute arbitrary code via an Alternate Data Stream (ADS) syntax in the filename parameter, as demonstrated using .htaccess::$DATA to upload a PHP program.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS12.39% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-94
On CISA KEVno
Public exploityes
Published2014-10-06
Last modified2026-06-17

Affected (2)

VendorProduct
owncloudowncloud
owncloudowncloud server

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD