CVE-2013-1939
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
14/03/2014
Last modified:
12/04/2025
Description
The HTML\Browser plugin in SabreDAV before 1.6.9, 1.7.x before 1.7.7, and 1.8.x before 1.8.5, as used in ownCloud, when running on Windows, does not properly check path separators in the base path, which allows remote attackers to read arbitrary files via a \ (backslash) character.
Impact
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:fruux:sabredav:*:*:*:*:*:*:*:* | 1.6.0 (including) | 1.6.9 (excluding) |
cpe:2.3:a:fruux:sabredav:*:*:*:*:*:*:*:* | 1.7.0 (including) | 1.7.7 (excluding) |
cpe:2.3:a:fruux:sabredav:*:*:*:*:*:*:*:* | 1.8.0 (including) | 1.8.5 (excluding) |
cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:* | ||
cpe:2.3:a:owncloud:owncloud_server:*:*:*:*:*:*:*:* | 4.0.0 (including) | 4.0.14 (excluding) |
cpe:2.3:a:owncloud:owncloud_server:*:*:*:*:*:*:*:* | 4.5.0 (including) | 4.5.9 (excluding) |
cpe:2.3:a:owncloud:owncloud_server:*:*:*:*:*:*:*:* | 5.0.0 (including) | 5.0.4 (excluding) |
cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page