| CVE-2012-4752 |
medium |
— |
5.0 |
|
|
owncloud |
14y ago |
appconfig.php in ownCloud before 4.0.6 does not properly restrict access, which allows remote authenticated users to edit app configurations via unspecified vectors. NOTE: this can be leveraged by u… |
| CVE-2012-4397 |
medium |
— |
4.3 |
|
|
owncloud |
14y ago |
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 4.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) calendar displayname to part.choosecalendar.rowf… |
| CVE-2012-4396 |
medium |
— |
4.3 |
|
|
owncloud |
14y ago |
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 4.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) file names to apps/user_ldap/settings.php; (2) u… |
| CVE-2012-4395 |
medium |
— |
4.3 |
|
|
owncloud |
14y ago |
Cross-site scripting (XSS) vulnerability in index.php in ownCloud before 4.0.3 allows remote attackers to inject arbitrary web script or HTML via the redirect_url parameter. |
| CVE-2012-4394 |
medium |
— |
4.3 |
|
|
owncloud |
14y ago |
Cross-site scripting (XSS) vulnerability in apps/files/js/filelist.js in ownCloud before 4.0.5 allows remote attackers to inject arbitrary web script or HTML via the file parameter. |
| CVE-2012-4393 |
medium |
— |
6.8 |
|
|
owncloud |
14y ago |
Multiple cross-site request forgery (CSRF) vulnerabilities in ownCloud before 4.0.6 allow remote attackers to hijack the authentication of arbitrary users for requests that use (1) addBookmark.php, (… |
| CVE-2012-4391 |
medium |
— |
6.8 |
|
|
owncloud |
14y ago |
Cross-site request forgery (CSRF) vulnerability in core/ajax/appconfig.php in ownCloud before 4.0.7 allows remote attackers to hijack the authentication of administrators for requests that edit the a… |
| CVE-2012-4390 |
medium |
— |
4.0 |
|
|
owncloud |
14y ago |
(1) apps/calendar/appinfo/remote.php and (2) apps/contacts/appinfo/remote.php in ownCloud before 4.0.7 allows remote authenticated users to enumerate the registered users via unspecified vectors. |
| CVE-2012-4389 |
medium |
— |
6.8 |
|
|
owncloud |
14y ago |
Incomplete blacklist vulnerability in lib/migrate.php in ownCloud before 4.0.7 allows remote attackers to execute arbitrary code by uploading a crafted .htaccess file in an import.zip file and access… |
| CVE-2012-2398 |
medium |
— |
4.3 |
|
|
owncloud |
14y ago |
Cross-site scripting (XSS) vulnerability in files/ajax/download.php in ownCloud before 3.0.3 allows remote attackers to inject arbitrary web script or HTML via the files parameter, a different vulner… |
| CVE-2012-2397 |
medium |
— |
6.8 |
|
|
owncloud |
14y ago |
Cross-site request forgery (CSRF) vulnerability in ownCloud before 3.0.3 allows remote attackers to hijack the authentication of arbitrary users for requests that insert cross-site scripting (XSS) se… |
| CVE-2012-2270 |
medium |
— |
6.8 |
EXP |
|
owncloud |
14y ago |
Open redirect vulnerability in index.php (aka the Login Page) in ownCloud before 3.0.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the r… |
| CVE-2012-2269 |
medium |
— |
4.3 |
|
|
owncloud |
14y ago |
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 3.0.3 allow remote attackers to inject arbitrary web script or HTML via (1) an arbitrary field to apps/contacts/ajax/addcard.php… |