« Volver al listado

CVE-2015-4717

Estado: ModificadaAlta (7.8)—

The filename sanitization component in ownCloud Server before 6.0.8, 7.0.x before 7.0.6, and 8.0.x before 8.0.4 does not properly handle $_GET parameters cast by PHP to an array, which allows remote attackers to cause a denial of service (infinite loop and log file consumption) via crafted endpoint file names.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2015-4717",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 6.9,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2015-10-21T18:59:01.517",
  "references": [
    {
      "url": "http://www.debian.org/security/2015/dsa-3373",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/76161",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://owncloud.org/security/advisory/?id=oc-sa-2015-007",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.debian.org/security/2015/dsa-3373",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/76161",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://owncloud.org/security/advisory/?id=oc-sa-2015-007",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-399"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The filename sanitization component in ownCloud Server before 6.0.8, 7.0.x before 7.0.6, and 8.0.x before 8.0.4 does not properly handle $_GET parameters cast by PHP to an array, which allows remote attackers to cause a denial of service (infinite loop and log file consumption) via crafted endpoint file names."
    },
    {
      "lang": "es",
      "value": "El componente de saneo de nombre de archivo en ownCloud Server en versiones anteriores a 6.0.8, 7.0.x en versiones anteriores a 7.0.6 y 8.0.x en versiones anteriores a 8.0.4 no maneja correctamente la proyección de parámetros $_GET por PHP a un array, lo que permite a atacantes remotos causar una denegación de servicio (bucle infinito y consumo del archivo log) a través de nombres de archivo de terminal manipulados."
    }
  ],
  "lastModified": "2026-06-17T00:27:46.227",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:owncloud:owncloud:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "45DD7E31-9A49-4154-9C26-89A389581E05",
              "versionEndIncluding": "6.0.7"
            },
            {
              "criteria": "cpe:2.3:a:owncloud:owncloud_server:7.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8850D462-7494-40AF-BA58-91AB3EC4688E"
            },
            {
              "criteria": "cpe:2.3:a:owncloud:owncloud_server:7.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C21CA18D-81F1-4B65-B46A-688D060F4E37"
            },
            {
              "criteria": "cpe:2.3:a:owncloud:owncloud_server:7.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AFF45C5A-FA91-4908-9396-984FA6DBF80B"
            },
            {
              "criteria": "cpe:2.3:a:owncloud:owncloud_server:7.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F0A9893F-0D5B-4DE5-B9D5-49AC2DA71BB8"
            },
            {
              "criteria": "cpe:2.3:a:owncloud:owncloud_server:7.0.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7F50E0BD-53F6-4BF5-8EDE-77711DC2EB04"
            },
            {
              "criteria": "cpe:2.3:a:owncloud:owncloud_server:7.0.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4B2107C8-4A67-4889-94B7-9DA5BBD9CB3E"
            },
            {
              "criteria": "cpe:2.3:a:owncloud:owncloud_server:8.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4D554B7F-DEC4-4238-9346-CD1E3B1223E5"
            },
            {
              "criteria": "cpe:2.3:a:owncloud:owncloud_server:8.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9E097A07-B9D8-4117-BCE5-32BCFF9905DB"
            },
            {
              "criteria": "cpe:2.3:a:owncloud:owncloud_server:8.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E52E7D8E-67EF-4EA9-9B3B-2E00F4A271C0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}