Show filters
160 Total Results
Displaying 31-40 of 160
Sort by:
Attacker Value
Unknown
CVE-2014-1665
Disclosure Date: March 20, 2018 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in ownCloud before 6.0.1 allows remote authenticated users to inject arbitrary web script or HTML via the filename of an uploaded file.
0
Attacker Value
Unknown
CVE-2017-8896
Disclosure Date: July 17, 2017 (last updated November 26, 2024)
ownCloud Server before 8.2.12, 9.0.x before 9.0.10, 9.1.x before 9.1.6, and 10.0.x before 10.0.2 are vulnerable to XSS on error pages by injecting code in url parameters.
0
Attacker Value
Unknown
CVE-2017-9339
Disclosure Date: July 17, 2017 (last updated November 26, 2024)
A logical error in ownCloud Server before 10.0.2 caused disclosure of valid share tokens for public calendars. Thus granting an attacker potentially access to publicly shared calendars without knowing the share token.
0
Attacker Value
Unknown
CVE-2017-9340
Disclosure Date: July 17, 2017 (last updated November 26, 2024)
An attacker is logged in as a normal user and can somehow make admin to delete shared folders in ownCloud Server before 10.0.2.
0
Attacker Value
Unknown
CVE-2017-9338
Disclosure Date: July 17, 2017 (last updated November 26, 2024)
Inadequate escaping lead to XSS vulnerability in the search module in ownCloud Server before 8.2.12, 9.0.x before 9.0.10, 9.1.x before 9.1.6, and 10.0.x before 10.0.2. To be exploitable a user has to write or paste malicious content into the search dialogue.
0
Attacker Value
Unknown
CVE-2016-9465
Disclosure Date: March 28, 2017 (last updated November 26, 2024)
Nextcloud Server before 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from Stored XSS in CardDAV image export. The CardDAV image export functionality as implemented in Nextcloud/ownCloud allows the download of images stored within a vCard. Due to not performing any kind of verification on the image content this is prone to a stored Cross-Site Scripting attack.
0
Attacker Value
Unknown
CVE-2016-9463
Disclosure Date: March 28, 2017 (last updated November 26, 2024)
Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.1.2, 9.0.6, and 8.2.9 suffer from SMB User Authentication Bypass. Nextcloud/ownCloud include an optional and not by default enabled SMB authentication component that allows authenticating users against an SMB server. This backend is implemented in a way that tries to connect to a SMB server and if that succeeded consider the user logged-in. The backend did not properly take into account SMB servers that have any kind of anonymous auth configured. This is the default on SMB servers nowadays and allows an unauthenticated attacker to gain access to an account without valid credentials. Note: The SMB backend is disabled by default and requires manual configuration in the Nextcloud/ownCloud config file. If you have not configured the SMB backend then you're not affected by this vulnerability.
0
Attacker Value
Unknown
CVE-2016-9459
Disclosure Date: March 28, 2017 (last updated November 26, 2024)
Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are vulnerable to a log pollution vulnerability potentially leading to a local XSS. The download log functionality in the admin screen is delivering the log in JSON format to the end-user. The file was delivered with an attachment disposition forcing the browser to download the document. However, Firefox running on Microsoft Windows would offer the user to open the data in the browser as an HTML document. Thus any injected data in the log would be executed.
0
Attacker Value
Unknown
CVE-2016-9468
Disclosure Date: March 28, 2017 (last updated November 26, 2024)
Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the dav app. The exception message displayed on the DAV endpoints contained partially user-controllable input leading to a potential misrepresentation of information.
0
Attacker Value
Unknown
CVE-2016-9466
Disclosure Date: March 28, 2017 (last updated November 26, 2024)
Nextcloud Server before 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from Reflected XSS in the Gallery application. The gallery app was not properly sanitizing exception messages from the Nextcloud/ownCloud server. Due to an endpoint where an attacker could influence the error message, this led to a reflected Cross-Site-Scripting vulnerability.
0