| CVE-2012-4394 |
medium |
— |
4.3 |
|
|
owncloud |
14y ago |
Cross-site scripting (XSS) vulnerability in apps/files/js/filelist.js in ownCloud before 4.0.5 allows remote attackers to inject arbitrary web script or HTML via the file parameter. |
| CVE-2012-4393 |
medium |
— |
6.8 |
|
|
owncloud |
14y ago |
Multiple cross-site request forgery (CSRF) vulnerabilities in ownCloud before 4.0.6 allow remote attackers to hijack the authentication of arbitrary users for requests that use (1) addBookmark.php, (… |
| CVE-2012-4392 |
high |
— |
7.5 |
|
|
owncloud |
14y ago |
index.php in ownCloud 4.0.7 does not properly validate the oc_token cookie, which allows remote attackers to bypass authentication via a crafted oc_token cookie value. |
| CVE-2012-4391 |
medium |
— |
6.8 |
|
|
owncloud |
14y ago |
Cross-site request forgery (CSRF) vulnerability in core/ajax/appconfig.php in ownCloud before 4.0.7 allows remote attackers to hijack the authentication of administrators for requests that edit the a… |
| CVE-2012-4390 |
medium |
— |
4.0 |
|
|
owncloud |
14y ago |
(1) apps/calendar/appinfo/remote.php and (2) apps/contacts/appinfo/remote.php in ownCloud before 4.0.7 allows remote authenticated users to enumerate the registered users via unspecified vectors. |
| CVE-2012-4389 |
medium |
— |
6.8 |
|
|
owncloud |
14y ago |
Incomplete blacklist vulnerability in lib/migrate.php in ownCloud before 4.0.7 allows remote attackers to execute arbitrary code by uploading a crafted .htaccess file in an import.zip file and access… |
| CVE-2012-2398 |
medium |
— |
4.3 |
|
|
owncloud |
14y ago |
Cross-site scripting (XSS) vulnerability in files/ajax/download.php in ownCloud before 3.0.3 allows remote attackers to inject arbitrary web script or HTML via the files parameter, a different vulner… |
| CVE-2012-2397 |
medium |
— |
6.8 |
|
|
owncloud |
14y ago |
Cross-site request forgery (CSRF) vulnerability in ownCloud before 3.0.3 allows remote attackers to hijack the authentication of arbitrary users for requests that insert cross-site scripting (XSS) se… |
| CVE-2012-2270 |
medium |
— |
6.8 |
EXP |
|
owncloud |
14y ago |
Open redirect vulnerability in index.php (aka the Login Page) in ownCloud before 3.0.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the r… |
| CVE-2012-2269 |
medium |
— |
4.3 |
|
|
owncloud |
14y ago |
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 3.0.3 allow remote attackers to inject arbitrary web script or HTML via (1) an arbitrary field to apps/contacts/ajax/addcard.php… |