Description
Incomplete blacklist vulnerability in ajax/upload.php in ownCloud before 5.0, when running on Windows, allows remote authenticated users to bypass intended access restrictions, upload files with arbitrary names, and execute arbitrary code via an Alternate Data Stream (ADS) syntax in the filename parameter, as demonstrated using .htaccess::$DATA to upload a PHP program.
Remediation
References
Related Vulnerabilities
WebLogic Use of a Broken or Risky Cryptographic Algorithm Vulnerability (CVE-2021-2351)
PHP Use After Free Vulnerability (CVE-2017-12932)
WordPress Plugin Cherry Multiple Vulnerabilities (1.2.6)
WordPress Plugin W3 Total Cache Multiple Vulnerabilities (0.9.4)
RubyGems Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2018-1000075)