Show filters
160 Total Results
Displaying 131-140 of 160
Sort by:
Attacker Value
Unknown

CVE-2013-0298

Disclosure Date: March 14, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 4.5.x before 4.5.7 allow remote attackers to inject arbitrary web script or HTML via (1) a crafted iCalendar file to the calendar application, the (2) dir or (3) file parameter to apps/files_pdfviewer/viewer.php, or the (4) mountpoint parameter to /apps/files_external/addMountPoint.php.
0
Attacker Value
Unknown

CVE-2013-2046

Disclosure Date: March 09, 2014 (last updated October 05, 2023)
SQL injection vulnerability in lib/bookmarks.php in ownCloud Server 4.5.x before 4.5.11 and 5.x before 5.0.6 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown

CVE-2013-1893

Disclosure Date: March 09, 2014 (last updated October 05, 2023)
SQL injection vulnerability in addressbookprovider.php in ownCloud Server before 5.0.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, related to the contacts application.
0
Attacker Value
Unknown

CVE-2013-2045

Disclosure Date: March 09, 2014 (last updated October 05, 2023)
SQL injection vulnerability in lib/db.php in ownCloud Server 5.0.x before 5.0.6 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown

CVE-2013-1890

Disclosure Date: March 09, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud Server before 5.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) new_name parameter to apps/bookmarks/ajax/renameTag.php or (2) multiple unspecified parameters to unknown files in apps/contacts/ajax/.
0
Attacker Value
Unknown

CVE-2013-1967

Disclosure Date: February 05, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in flashmediaelement.swf in MediaElement.js before 2.11.2, as used in ownCloud Server 5.0.x before 5.0.5 and 4.5.x before 4.5.10, allows remote attackers to inject arbitrary web script or HTML via the file parameter.
0
Attacker Value
Unknown

CVE-2013-6403

Disclosure Date: December 24, 2013 (last updated October 05, 2023)
The admin page in ownCloud before 5.0.13 allows remote attackers to bypass intended access restrictions via unspecified vectors, related to MariaDB.
0
Attacker Value
Unknown

CVE-2013-1942

Disclosure Date: August 15, 2013 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in actionscript/Jplayer.as in the Flash SWF component (jplayer.swf) in jPlayer before 2.2.20, as used in ownCloud Server before 5.0.4 and other products, allow remote attackers to inject arbitrary web script or HTML via the (1) jQuery or (2) id parameters, as demonstrated using document.write in the jQuery parameter, a different vulnerability than CVE-2013-2022 and CVE-2013-2023.
0
Attacker Value
Unknown

CVE-2012-5666

Disclosure Date: January 03, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in bookmarks/js/bookmarks.js in ownCloud 4.0.x before 4.0.10 and 4.5.x before 4.5.5 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to apps/bookmark/index.php.
0
Attacker Value
Unknown

CVE-2012-5665

Disclosure Date: January 03, 2013 (last updated October 05, 2023)
ownCloud 4.0.x before 4.0.10 and 4.5.x before 4.5.5 does not properly restrict access to settings.php, which allows remote attackers to edit app configurations of user_webdavauth and user_ldap by editing this file.
0