ownCloud Files or Directories Accessible to External Parties Vulnerability - CVE-2015-4715 - Vulnerability Database

ownCloud Files or Directories Accessible to External Parties Vulnerability - CVE-2015-4715

Medium
Reference: CVE-2015-4715
Title: ownCloud Files or Directories Accessible to External Parties Vulnerability
Overview:

The fetch function in OAuth/Curl.php in Dropbox-PHP as used in ownCloud Server before 6.0.8 7.x before 7.0.6 and 8.x before 8.0.4 when an external Dropbox storage has been mounted allows remote administrators of Dropbox.com to read arbitrary files via an (at sign) character in unspecified POST values.