Show filters
26 Total Results
Displaying 21-26 of 26
Sort by:
Attacker Value
Unknown
CVE-2012-5665
Disclosure Date: January 03, 2013 (last updated October 05, 2023)
ownCloud 4.0.x before 4.0.10 and 4.5.x before 4.5.5 does not properly restrict access to settings.php, which allows remote attackers to edit app configurations of user_webdavauth and user_ldap by editing this file.
0
Attacker Value
Unknown
CVE-2012-5607
Disclosure Date: December 18, 2012 (last updated October 05, 2023)
The "Lost Password" reset functionality in ownCloud before 4.0.9 and 4.5.0 does not properly check the security token, which allows remote attackers to change an accounts password via unspecified vectors related to a "Remote Timing Attack."
0
Attacker Value
Unknown
CVE-2012-5609
Disclosure Date: December 18, 2012 (last updated October 05, 2023)
Incomplete blacklist vulnerability in lib/migrate.php in ownCloud before 4.5.2 allows remote authenticated users to execute arbitrary PHP code by uploading a crafted mount.php file in a ZIP file.
0
Attacker Value
Unknown
CVE-2012-5610
Disclosure Date: December 18, 2012 (last updated October 05, 2023)
Incomplete blacklist vulnerability in lib/filesystem.php in ownCloud before 4.0.9 and 4.5.x before 4.5.2 allows remote authenticated users to execute arbitrary PHP code by uploading a file with a special crafted name.
0
Attacker Value
Unknown
CVE-2012-5606
Disclosure Date: December 18, 2012 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 4.0.9 and 4.5.0 allow remote attackers to inject arbitrary web script or HTML via the (1) file name to apps/files_versions/js/versions.js or (2) apps/files/js/filelist.js; or (3) event title to 3rdparty/fullcalendar/js/fullcalendar.js.
0
Attacker Value
Unknown
CVE-2012-4392
Disclosure Date: September 05, 2012 (last updated October 05, 2023)
index.php in ownCloud 4.0.7 does not properly validate the oc_token cookie, which allows remote attackers to bypass authentication via a crafted oc_token cookie value.
0