← Back

CVE-2013-1939

nvd nist
Published: Mar 14, 2014Modified: May 6, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

The HTML\Browser plugin in SabreDAV before 1.6.9, 1.7.x before 1.7.7, and 1.8.x before 1.8.5, as used in ownCloud, when running on Windows, does not properly check path separators in the base path, which allows remote attackers to read arbitrary files via a \ (backslash) character.

Affected (6)

1 product
Sabredav
1 product
Owncloud Server
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Fruux
From 1.6.0 to 1.6.9
From 1.7.0 to 1.7.7
From 1.8.0 to 1.8.5
Configuration B
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Owncloud
From 4.0.0 to 4.0.14
From 4.5.0 to 4.5.9
From 5.0.0 to 5.0.4
Running on/withPlatform Versions
Microsoft
Windows
All versions

Timeline

No history available yet.