| |
Vulnerability CVE-2013-1963
Published: 2014-03-14 Modified: 2014-03-18
Description: |
The contacts application in ownCloud before 4.5.10 and 5.x before 5.0.5 does not properly check the ownership of contacts, which allows remote authenticated users to download arbitrary contacts via unspecified vectors. |
See advisories in our WLB2 database: | Topic | Author | Date |
Med. |
| ownCloud | 22.04.2013 |
Type:
CWE-264 (Permissions, Privileges, and Access Controls)
CVSS2 => (AV:N/AC:L/Au:S/C:P/I:N/A:N)
CVSS Base Score |
Impact Subscore |
Exploitability Subscore |
4/10 |
2.9/10 |
8/10 |
Exploit range |
Attack complexity |
Authentication |
Remote |
Low |
Single time |
Confidentiality impact |
Integrity impact |
Availability impact |
Partial |
None |
None |
References: |
http://owncloud.org/about/security/advisories/oC-SA-2013-018/
|
|
|
closedb();
?>
Copyright 2024, cxsecurity.com
|
|
|