The external SMB storage driver in ownCloud Server before 6.0.8, 7.0.x before 7.0.6, and 8.0.x before 8.0.4 allows remote authenticated users to execute arbitrary SMB commands via a ; (semicolon) character in a file.
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
Link | Tags |
---|---|
http://www.debian.org/security/2015/dsa-3373 | vendor advisory |
http://www.securityfocus.com/bid/76162 | vdb entry |
https://owncloud.org/security/advisory/?id=oc-sa-2015-008 | vendor advisory |