The fetch function in OAuth/Curl.php in Dropbox-PHP, as used in ownCloud Server before 6.0.8, 7.x before 7.0.6, and 8.x before 8.0.4 when an external Dropbox storage has been mounted, allows remote administrators of Dropbox.com to read arbitrary files via an @ (at sign) character in unspecified POST values.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/76158 | Third Party Advisory VDB Entry |
https://github.com/owncloud/core/commit/bf0f1a50926a75a26a42a3da4d62e84a489ee77a | Patch Third Party Advisory |
https://owncloud.org/security/advisories/mounted-dropbox-storage-allows-dropbox-com-access-file/ | Vendor Advisory |
https://owncloud.org/security/advisory/?id=oc-sa-2015-005 | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2020-02-17T18:09:59
Updated: 2020-02-17T18:09:59
Reserved: 2015-06-22T00:00:00
Link: CVE-2015-4715
JSON object: View
NVD Information
Status : Analyzed
Published: 2020-02-17T19:15:11.227
Modified: 2020-02-28T19:31:11.137
Link: CVE-2015-4715
JSON object: View
Redhat Information
No data.
CWE