Show filters
31 Total Results
Displaying 21-30 of 31
Sort by:
Attacker Value
Unknown
CVE-2013-0307
Disclosure Date: March 14, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in settings.php in ownCloud before 4.0.12 and 4.5.x before 4.5.7 allows remote administrators to inject arbitrary web script or HTML via the group input field parameter.
0
Attacker Value
Unknown
CVE-2013-1942
Disclosure Date: August 15, 2013 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in actionscript/Jplayer.as in the Flash SWF component (jplayer.swf) in jPlayer before 2.2.20, as used in ownCloud Server before 5.0.4 and other products, allow remote attackers to inject arbitrary web script or HTML via the (1) jQuery or (2) id parameters, as demonstrated using document.write in the jQuery parameter, a different vulnerability than CVE-2013-2022 and CVE-2013-2023.
0
Attacker Value
Unknown
CVE-2012-5666
Disclosure Date: January 03, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in bookmarks/js/bookmarks.js in ownCloud 4.0.x before 4.0.10 and 4.5.x before 4.5.5 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to apps/bookmark/index.php.
0
Attacker Value
Unknown
CVE-2012-5665
Disclosure Date: January 03, 2013 (last updated October 05, 2023)
ownCloud 4.0.x before 4.0.10 and 4.5.x before 4.5.5 does not properly restrict access to settings.php, which allows remote attackers to edit app configurations of user_webdavauth and user_ldap by editing this file.
0
Attacker Value
Unknown
CVE-2012-5607
Disclosure Date: December 18, 2012 (last updated October 05, 2023)
The "Lost Password" reset functionality in ownCloud before 4.0.9 and 4.5.0 does not properly check the security token, which allows remote attackers to change an accounts password via unspecified vectors related to a "Remote Timing Attack."
0
Attacker Value
Unknown
CVE-2012-5609
Disclosure Date: December 18, 2012 (last updated October 05, 2023)
Incomplete blacklist vulnerability in lib/migrate.php in ownCloud before 4.5.2 allows remote authenticated users to execute arbitrary PHP code by uploading a crafted mount.php file in a ZIP file.
0
Attacker Value
Unknown
CVE-2012-5610
Disclosure Date: December 18, 2012 (last updated October 05, 2023)
Incomplete blacklist vulnerability in lib/filesystem.php in ownCloud before 4.0.9 and 4.5.x before 4.5.2 allows remote authenticated users to execute arbitrary PHP code by uploading a file with a special crafted name.
0
Attacker Value
Unknown
CVE-2012-5606
Disclosure Date: December 18, 2012 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 4.0.9 and 4.5.0 allow remote attackers to inject arbitrary web script or HTML via the (1) file name to apps/files_versions/js/versions.js or (2) apps/files/js/filelist.js; or (3) event title to 3rdparty/fullcalendar/js/fullcalendar.js.
0
Attacker Value
Unknown
CVE-2012-4389
Disclosure Date: September 05, 2012 (last updated October 05, 2023)
Incomplete blacklist vulnerability in lib/migrate.php in ownCloud before 4.0.7 allows remote attackers to execute arbitrary code by uploading a crafted .htaccess file in an import.zip file and accessing an uploaded PHP file.
0
Attacker Value
Unknown
CVE-2012-4390
Disclosure Date: September 05, 2012 (last updated October 05, 2023)
(1) apps/calendar/appinfo/remote.php and (2) apps/contacts/appinfo/remote.php in ownCloud before 4.0.7 allows remote authenticated users to enumerate the registered users via unspecified vectors.
0