| CVE-2012-5608 |
medium |
— |
4.3 |
|
|
owncloud |
14y ago |
Cross-site scripting (XSS) vulnerability in apps/user_webdavauth/settings.php in ownCloud 4.5.x before 4.5.2 allows remote attackers to inject arbitrary web script or HTML via arbitrary POST paramete… |
| CVE-2012-5607 |
medium |
— |
5.0 |
|
|
owncloud |
14y ago |
The "Lost Password" reset functionality in ownCloud before 4.0.9 and 4.5.0 does not properly check the security token, which allows remote attackers to change an accounts password via unspecified vec… |
| CVE-2012-5606 |
medium |
— |
4.3 |
|
|
owncloud |
14y ago |
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 4.0.9 and 4.5.0 allow remote attackers to inject arbitrary web script or HTML via the (1) file name to apps/files_versions/js/ve… |
| CVE-2012-4753 |
medium |
— |
6.8 |
|
|
owncloud |
14y ago |
Multiple cross-site request forgery (CSRF) vulnerabilities in ownCloud before 4.0.5 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors. |
| CVE-2012-4752 |
medium |
— |
5.0 |
|
|
owncloud |
14y ago |
appconfig.php in ownCloud before 4.0.6 does not properly restrict access, which allows remote authenticated users to edit app configurations via unspecified vectors. NOTE: this can be leveraged by u… |
| CVE-2012-4397 |
medium |
— |
4.3 |
|
|
owncloud |
14y ago |
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 4.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) calendar displayname to part.choosecalendar.rowf… |
| CVE-2012-4396 |
medium |
— |
4.3 |
|
|
owncloud |
14y ago |
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 4.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) file names to apps/user_ldap/settings.php; (2) u… |
| CVE-2012-4395 |
medium |
— |
4.3 |
|
|
owncloud |
14y ago |
Cross-site scripting (XSS) vulnerability in index.php in ownCloud before 4.0.3 allows remote attackers to inject arbitrary web script or HTML via the redirect_url parameter. |
| CVE-2012-4394 |
medium |
— |
4.3 |
|
|
owncloud |
14y ago |
Cross-site scripting (XSS) vulnerability in apps/files/js/filelist.js in ownCloud before 4.0.5 allows remote attackers to inject arbitrary web script or HTML via the file parameter. |
| CVE-2012-4393 |
medium |
— |
6.8 |
|
|
owncloud |
14y ago |
Multiple cross-site request forgery (CSRF) vulnerabilities in ownCloud before 4.0.6 allow remote attackers to hijack the authentication of arbitrary users for requests that use (1) addBookmark.php, (… |
| CVE-2012-4391 |
medium |
— |
6.8 |
|
|
owncloud |
14y ago |
Cross-site request forgery (CSRF) vulnerability in core/ajax/appconfig.php in ownCloud before 4.0.7 allows remote attackers to hijack the authentication of administrators for requests that edit the a… |
| CVE-2012-4390 |
medium |
— |
4.0 |
|
|
owncloud |
14y ago |
(1) apps/calendar/appinfo/remote.php and (2) apps/contacts/appinfo/remote.php in ownCloud before 4.0.7 allows remote authenticated users to enumerate the registered users via unspecified vectors. |
| CVE-2012-4389 |
medium |
— |
6.8 |
|
|
owncloud |
14y ago |
Incomplete blacklist vulnerability in lib/migrate.php in ownCloud before 4.0.7 allows remote attackers to execute arbitrary code by uploading a crafted .htaccess file in an import.zip file and access… |
| CVE-2012-2398 |
medium |
— |
4.3 |
|
|
owncloud |
14y ago |
Cross-site scripting (XSS) vulnerability in files/ajax/download.php in ownCloud before 3.0.3 allows remote attackers to inject arbitrary web script or HTML via the files parameter, a different vulner… |
| CVE-2012-2397 |
medium |
— |
6.8 |
|
|
owncloud |
14y ago |
Cross-site request forgery (CSRF) vulnerability in ownCloud before 3.0.3 allows remote attackers to hijack the authentication of arbitrary users for requests that insert cross-site scripting (XSS) se… |
| CVE-2012-2270 |
medium |
— |
6.8 |
EXP |
|
owncloud |
14y ago |
Open redirect vulnerability in index.php (aka the Login Page) in ownCloud before 3.0.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the r… |
| CVE-2012-2269 |
medium |
— |
4.3 |
|
|
owncloud |
14y ago |
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 3.0.3 allow remote attackers to inject arbitrary web script or HTML via (1) an arbitrary field to apps/contacts/ajax/addcard.php… |