Show filters
160 Total Results
Displaying 121-130 of 160
Sort by:
Attacker Value
Unknown
CVE-2013-2039
Disclosure Date: March 14, 2014 (last updated October 05, 2023)
Directory traversal vulnerability in lib/files/view.php in ownCloud before 4.0.15, 4.5.x 4.5.11, and 5.x before 5.0.6 allows remote authenticated users to access arbitrary files via unspecified vectors.
0
Attacker Value
Unknown
CVE-2013-1850
Disclosure Date: March 14, 2014 (last updated October 05, 2023)
Multiple incomplete blacklist vulnerabilities in (1) import.php and (2) ajax/uploadimport.php in apps/contacts/ in ownCloud before 4.0.13 and 4.5.x before 4.5.8 allow remote authenticated users to execute arbitrary PHP code by uploading a .htaccess file.
0
Attacker Value
Unknown
CVE-2013-1822
Disclosure Date: March 14, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 4.5.x before 4.5.8 allow remote authenticated users with administrator privileges to inject arbitrary web script or HTML via the (1) quota parameter to /core/settings/ajax/setquota.php, or remote authenticated users with group admin privileges to inject arbitrary web script or HTML via the (2) group field to settings.php or (3) "share with" field.
0
Attacker Value
Unknown
CVE-2013-2150
Disclosure Date: March 14, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in js/viewer.js in ownCloud before 4.5.12 and 5.x before 5.0.7 allow remote attackers to inject arbitrary web script or HTML via vectors related to shared files.
0
Attacker Value
Unknown
CVE-2013-2044
Disclosure Date: March 14, 2014 (last updated October 05, 2023)
Open redirect vulnerability in the Login Page (index.php) in ownCloud before 5.0.6 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect_url parameter.
0
Attacker Value
Unknown
CVE-2013-1939
Disclosure Date: March 14, 2014 (last updated October 05, 2023)
The HTML\Browser plugin in SabreDAV before 1.6.9, 1.7.x before 1.7.7, and 1.8.x before 1.8.5, as used in ownCloud, when running on Windows, does not properly check path separators in the base path, which allows remote attackers to read arbitrary files via a \ (backslash) character.
0
Attacker Value
Unknown
CVE-2013-2149
Disclosure Date: March 14, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 4.0.16 and 5.x before 5.0.7 allow remote authenticated users to inject arbitrary web script or HTML via vectors related to shared files.
0
Attacker Value
Unknown
CVE-2013-2043
Disclosure Date: March 14, 2014 (last updated October 05, 2023)
apps/calendar/ajax/events.php in ownCloud before 4.5.11 and 5.x before 5.0.6 does not properly check the ownership of a calendar, which allows remote authenticated users to download arbitrary calendars via the calendar_id parameter.
0
Attacker Value
Unknown
CVE-2013-0297
Disclosure Date: March 14, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 4.0.12 and 4.5.x before 4.5.7 allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) site_name or (2) site_url parameter to apps/external/ajax/setsites.php.
0
Attacker Value
Unknown
CVE-2013-0307
Disclosure Date: March 14, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in settings.php in ownCloud before 4.0.12 and 4.5.x before 4.5.7 allows remote administrators to inject arbitrary web script or HTML via the group input field parameter.
0