Skip to content

CVE-2013-1939

The HTML\Browser plugin in SabreDAV before 1.6.9, 1.7.x before 1.7.7, and 1.8.x before 1.8.5, as used in ownCloud, when running on Windows, does not properly check path separators in the base path, which allows remote attackers to read arbitrary files via a \ (backslash) character.

View on NVD

Severity

N/A

EPSS

Probability of exploitation (next 30 days): 0.0029 (0.3%)
Percentile: 52.1%
EPSS: 2026-05-06

Affects

fruux:sabredavmicrosoft:windowsowncloud:owncloud_server

Technical description

The HTML\Browser plugin in SabreDAV before 1.6.9, 1.7.x before 1.7.7, and 1.8.x before 1.8.5, as used in ownCloud, when running on Windows, does not properly check path separators in the base path, which allows remote attackers to read arbitrary files via a \ (backslash) character.

Published: 3/14/2014, 4:55:04 PM
Last modified: 5/6/2026, 10:30:45 PM

References

HomeEventsBlogResourcesTeam