VYPR
Medium severity4.9NVD Advisory· Published Feb 17, 2020· Updated Jun 17, 2026

CVE-2015-4715

CVE-2015-4715

Description

The fetch function in OAuth/Curl.php in Dropbox-PHP, as used in ownCloud Server before 6.0.8, 7.x before 7.0.6, and 8.x before 8.0.4 when an external Dropbox storage has been mounted, allows remote administrators of Dropbox.com to read arbitrary files via an @ (at sign) character in unspecified POST values.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • OwnCloud/Owncloud2 versions
    cpe:2.3:a:owncloud:owncloud:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:owncloud:owncloud:*:*:*:*:*:*:*:*range: <6.0.8
    • (no CPE)range: <6.0.8, <7.0.6, <8.0.4
  • cpe:2.3:a:owncloud:owncloud_server:*:*:*:*:*:*:*:*
    Range: >=7.0.0,<7.0.6
  • ownCloud/Dropbox-PHPdescription

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.