Unrated severityNVD Advisory· Published Mar 14, 2014· Updated May 6, 2026
CVE-2013-1851
CVE-2013-1851
Description
Incomplete blacklist vulnerability in lib/migrate.php in ownCloud before 4.0.13 and 4.5.x before 4.5.8, when the user_migrate application is enabled, allows remote authenticated users to import arbitrary files to the user's account via unspecified vectors.
Affected products
26cpe:2.3:a:owncloud:owncloud_server:3.0.0:*:*:*:*:*:*:*+ 23 more
- cpe:2.3:a:owncloud:owncloud_server:3.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:3.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:3.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:3.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:4.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:4.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:4.0.10:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:4.0.11:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:4.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:4.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:4.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:4.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:4.0.6:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:4.0.7:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:4.0.8:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:4.0.9:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:4.5.0:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:4.5.1:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:4.5.2:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:4.5.3:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:4.5.4:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:4.5.5:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:4.5.6:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:4.5.7:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- owncloud.org/about/security/advisories/oC-SA-2013-010/nvdVendor Advisory
News mentions
0No linked articles in our index yet.