RSS   Vulnerabilities for 'Owncloud server'   RSS

2017-07-17
 
CVE-2017-9340

CWE-noinfo
 

 
An attacker is logged in as a normal user and can somehow make admin to delete shared folders in ownCloud Server before 10.0.2.

 
 
CVE-2017-9339

 

 
A logical error in ownCloud Server before 10.0.2 caused disclosure of valid share tokens for public calendars. Thus granting an attacker potentially access to publicly shared calendars without knowing the share token.

 
 
CVE-2017-9338

 

 
Inadequate escaping lead to XSS vulnerability in the search module in ownCloud Server before 8.2.12, 9.0.x before 9.0.10, 9.1.x before 9.1.6, and 10.0.x before 10.0.2. To be exploitable a user has to write or paste malicious content into the search dialogue.

 
 
CVE-2017-8896

CWE-79
 

 
ownCloud Server before 8.2.12, 9.0.x before 9.0.10, 9.1.x before 9.1.6, and 10.0.x before 10.0.2 are vulnerable to XSS on error pages by injecting code in url parameters.

 

 >>> Vendor: Owncloud 8 Products
Owncloud
SMB
Owncloud desktop client
Owncloud desktop
Owncloud server
File firewall
User ldap
Files antivirus


Copyright 2022, cxsecurity.com

 

Back to Top