Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The HTML\Browser plugin in SabreDAV before 1.6.9, 1.7.x before 1.7.7, and 1.8.x before 1.8.5, as used in ownCloud, when running on Windows, does not properly check path separators in the base path, which allows remote attackers to read arbitrary files via a \ (backslash) character.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SabreDAV 本地文件泄露漏洞
Vulnerability Description
SabreDAV是一套开源的WebDAV(基于万维网的分布式创作和版本控制)系统。该系统支持多种客户端,包括 Mac OS X Finder、Windows XP Finder和DavFS2等。 ownCloud中使用的SabreDAV的HTML\Browser插件存在安全漏洞。该漏洞源于当运行在Windows平台上,程序没有正确检查路径分隔符。远程攻击者可借助‘\’字符利用该漏洞读取任意文件。以下版本受到影响:1.6.8及之前的版本,1.7.7之前的1.7.x版本,1.8.5之前的1.8.x版本。
CVSS Information
N/A
Vulnerability Type
N/A