Show filters
37 Total Results
Displaying 31-37 of 37
Sort by:
Attacker Value
Unknown
CVE-2013-2044
Disclosure Date: March 14, 2014 (last updated October 05, 2023)
Open redirect vulnerability in the Login Page (index.php) in ownCloud before 5.0.6 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect_url parameter.
0
Attacker Value
Unknown
CVE-2013-2043
Disclosure Date: March 14, 2014 (last updated October 05, 2023)
apps/calendar/ajax/events.php in ownCloud before 4.5.11 and 5.x before 5.0.6 does not properly check the ownership of a calendar, which allows remote authenticated users to download arbitrary calendars via the calendar_id parameter.
0
Attacker Value
Unknown
CVE-2013-2046
Disclosure Date: March 09, 2014 (last updated October 05, 2023)
SQL injection vulnerability in lib/bookmarks.php in ownCloud Server 4.5.x before 4.5.11 and 5.x before 5.0.6 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown
CVE-2013-2045
Disclosure Date: March 09, 2014 (last updated October 05, 2023)
SQL injection vulnerability in lib/db.php in ownCloud Server 5.0.x before 5.0.6 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown
CVE-2013-1967
Disclosure Date: February 05, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in flashmediaelement.swf in MediaElement.js before 2.11.2, as used in ownCloud Server 5.0.x before 5.0.5 and 4.5.x before 4.5.10, allows remote attackers to inject arbitrary web script or HTML via the file parameter.
0
Attacker Value
Unknown
CVE-2013-6403
Disclosure Date: December 24, 2013 (last updated October 05, 2023)
The admin page in ownCloud before 5.0.13 allows remote attackers to bypass intended access restrictions via unspecified vectors, related to MariaDB.
0
Attacker Value
Unknown
CVE-2013-1942
Disclosure Date: August 15, 2013 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in actionscript/Jplayer.as in the Flash SWF component (jplayer.swf) in jPlayer before 2.2.20, as used in ownCloud Server before 5.0.4 and other products, allow remote attackers to inject arbitrary web script or HTML via the (1) jQuery or (2) id parameters, as demonstrated using document.write in the jQuery parameter, a different vulnerability than CVE-2013-2022 and CVE-2013-2023.
0