← Back

CVE-2012-4389

nvd nist
Published: Sep 5, 2012Modified: Apr 29, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

Incomplete blacklist vulnerability in lib/migrate.php in ownCloud before 4.0.7 allows remote attackers to execute arbitrary code by uploading a crafted .htaccess file in an import.zip file and accessing an uploaded PHP file.

Affected (11)

2 products
Owncloud
Owncloud Server
Configuration A
11 vulnerable
Vulnerable SoftwareAffected Versions
Up to 4.0.6
Owncloud
Version 3.0.0
Version 3.0.1
Version 3.0.2
Version 3.0.3
Version 4.0.0
Version 4.0.1
Version 4.0.2
Version 4.0.3
Version 4.0.4
Version 4.0.5

References (4)

Timeline

No history available yet.