Show filters
160 Total Results
Displaying 111-120 of 160
Sort by:
Attacker Value
Unknown

CVE-2013-2042

Disclosure Date: March 14, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 4.0.15, 4.5.x before 4.5.11, and 5.0.x before 5.0.6 allow remote authenticated users to inject arbitrary web script or HTML via the url parameter to (1) apps/bookmarks/ajax/addBookmark.php or (2) apps/bookmarks/ajax/editBookmark.php.
0
Attacker Value
Unknown

CVE-2014-2047

Disclosure Date: March 14, 2014 (last updated October 05, 2023)
Session fixation vulnerability in ownCloud before 6.0.2, when PHP is configured to accept session parameters through a GET request, allows remote attackers to hijack web sessions via unspecified vectors.
0
Attacker Value
Unknown

CVE-2013-1963

Disclosure Date: March 14, 2014 (last updated October 05, 2023)
The contacts application in ownCloud before 4.5.10 and 5.x before 5.0.5 does not properly check the ownership of contacts, which allows remote authenticated users to download arbitrary contacts via unspecified vectors.
0
Attacker Value
Unknown

CVE-2013-1851

Disclosure Date: March 14, 2014 (last updated October 05, 2023)
Incomplete blacklist vulnerability in lib/migrate.php in ownCloud before 4.0.13 and 4.5.x before 4.5.8, when the user_migrate application is enabled, allows remote authenticated users to import arbitrary files to the user's account via unspecified vectors.
0
Attacker Value
Unknown

CVE-2014-2049

Disclosure Date: March 14, 2014 (last updated October 05, 2023)
The default Flash Cross Domain policies in ownCloud before 5.0.15 and 6.x before 6.0.2 allows remote attackers to access user files via unspecified vectors.
0
Attacker Value
Unknown

CVE-2013-2040

Disclosure Date: March 14, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 4.0.15, 4.5.x before 4.5.11, and 5.0.x before 5.0.6 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2013-2086

Disclosure Date: March 14, 2014 (last updated October 05, 2023)
The configuration loader in ownCloud 5.0.x before 5.0.6 allows remote attackers to obtain CSRF tokens and other sensitive information by reading an unspecified JavaScript file.
0
Attacker Value
Unknown

CVE-2013-2041

Disclosure Date: March 14, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 5.0.x before 5.0.6 allow remote authenticated users to inject arbitrary web script or HTML via the (1) tag parameter to apps/bookmarks/ajax/addBookmark.php or (2) dir parameter to apps/files/ajax/newfile.php, which is passed to apps/files/js/files.js.
0
Attacker Value
Unknown

CVE-2013-2047

Disclosure Date: March 14, 2014 (last updated October 05, 2023)
The login page (aka index.php) in ownCloud before 5.0.6 does not disable the autocomplete setting for the password parameter, which makes it easier for physically proximate attackers to guess the password.
0
Attacker Value
Unknown

CVE-2013-2089

Disclosure Date: March 14, 2014 (last updated October 05, 2023)
Incomplete blacklist vulnerability in ownCloud before 5.0.6 allows remote authenticated users to execute arbitrary PHP code by uploading a crafted file, then accessing it via a direct request to the file in /data.
0