Medium severity4.9NVD Advisory· Published Feb 17, 2020· Updated Jun 17, 2026
CVE-2015-4715
CVE-2015-4715
Description
The fetch function in OAuth/Curl.php in Dropbox-PHP, as used in ownCloud Server before 6.0.8, 7.x before 7.0.6, and 8.x before 8.0.4 when an external Dropbox storage has been mounted, allows remote administrators of Dropbox.com to read arbitrary files via an @ (at sign) character in unspecified POST values.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- ownCloud/Dropbox-PHPdescription
Patches
Vulnerability mechanics
References
4- github.com/owncloud/core/commit/bf0f1a50926a75a26a42a3da4d62e84a489ee77anvdPatchThird Party Advisory
- www.securityfocus.com/bid/76158nvdThird Party AdvisoryVDB Entry
- owncloud.org/security/advisories/mounted-dropbox-storage-allows-dropbox-com-access-file/nvdVendor Advisory
- owncloud.org/security/advisory/nvdVendor Advisory
News mentions
0No linked articles in our index yet.