Owncloud

Owncloud

116 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.26%
  • Published 09.02.2021 19:15:13
  • Last modified 21.11.2024 05:23:05

Deleting users with certain names caused system files to be deleted. Risk is higher for systems which allow users to register themselves and have the data directory in the web root. This affects ownCloud/core versions < 10.6.

  • EPSS 0.37%
  • Published 15.01.2021 18:15:13
  • Last modified 21.11.2024 05:07:02

ownCloud (Core) before 10.5 allows XSS in login page 'forgot password.'

  • EPSS 1.36%
  • Published 17.02.2020 19:15:11
  • Last modified 31.03.2025 11:54:18

The fetch function in OAuth/Curl.php in Dropbox-PHP, as used in ownCloud Server before 6.0.8, 7.x before 7.0.6, and 8.x before 8.0.4 when an external Dropbox storage has been mounted, allows remote administrators of Dropbox.com to read arbitrary file...

  • EPSS 0.99%
  • Published 11.02.2020 16:15:12
  • Last modified 31.03.2025 11:54:18

Zend Framework, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.

  • EPSS 0.25%
  • Published 23.01.2020 20:15:11
  • Last modified 31.03.2025 11:54:18

Cross-site request forgery (CSRF) vulnerability in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2 allows remote attackers to hijack the authentication of users for requests that reset passwords via a crafted HTTP Host header.

  • EPSS 0.24%
  • Published 22.11.2019 19:15:11
  • Last modified 31.03.2025 11:54:18

Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 4.5.5, 4.0.10, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) unspecified parameters to apps/calendar/ajax/event/new.php or (2) url parameter to ap...

  • EPSS 0.86%
  • Published 26.03.2018 18:29:00
  • Last modified 21.11.2024 02:05:32

The user_openid app in ownCloud Server before 5.0.15 allows remote attackers to obtain access by leveraging an insecure OpenID implementation.

Exploit
  • EPSS 0.34%
  • Published 20.03.2018 21:29:00
  • Last modified 21.11.2024 02:04:47

Cross-site scripting (XSS) vulnerability in ownCloud before 6.0.1 allows remote authenticated users to inject arbitrary web script or HTML via the filename of an uploaded file.

  • EPSS 0.38%
  • Published 17.07.2017 21:29:00
  • Last modified 20.04.2025 01:37:25

ownCloud Server before 8.2.12, 9.0.x before 9.0.10, 9.1.x before 9.1.6, and 10.0.x before 10.0.2 are vulnerable to XSS on error pages by injecting code in url parameters.

  • EPSS 0.24%
  • Published 17.07.2017 21:29:00
  • Last modified 20.04.2025 01:37:25

Inadequate escaping lead to XSS vulnerability in the search module in ownCloud Server before 8.2.12, 9.0.x before 9.0.10, 9.1.x before 9.1.6, and 10.0.x before 10.0.2. To be exploitable a user has to write or paste malicious content into the search d...