| |
Vulnerability CVE-2017-9339
Published: 2017-07-17 Modified: 2017-07-18
Description: |
A logical error in ownCloud Server before 10.0.2 caused disclosure of valid share tokens for public calendars. Thus granting an attacker potentially access to publicly shared calendars without knowing the share token. |
CVSS2 => (AV:N/AC:L/Au:N/C:P/I:N/A:N)
CVSS Base Score |
Impact Subscore |
Exploitability Subscore |
5/10 |
2.9/10 |
10/10 |
Exploit range |
Attack complexity |
Authentication |
Remote |
Low |
No required |
Confidentiality impact |
Integrity impact |
Availability impact |
Partial |
None |
None |
References: |
https://owncloud.org/security/advisory/?id=oc-sa-2017-005
|
|
|
closedb();
?>
Copyright 2024, cxsecurity.com
|
|
|