Owncloud

Owncloud

116 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.26%
  • Veröffentlicht 09.02.2021 19:15:13
  • Zuletzt bearbeitet 21.11.2024 05:23:05

Deleting users with certain names caused system files to be deleted. Risk is higher for systems which allow users to register themselves and have the data directory in the web root. This affects ownCloud/core versions < 10.6.

  • EPSS 0.37%
  • Veröffentlicht 15.01.2021 18:15:13
  • Zuletzt bearbeitet 21.11.2024 05:07:02

ownCloud (Core) before 10.5 allows XSS in login page 'forgot password.'

  • EPSS 1.36%
  • Veröffentlicht 17.02.2020 19:15:11
  • Zuletzt bearbeitet 31.03.2025 11:54:18

The fetch function in OAuth/Curl.php in Dropbox-PHP, as used in ownCloud Server before 6.0.8, 7.x before 7.0.6, and 8.x before 8.0.4 when an external Dropbox storage has been mounted, allows remote administrators of Dropbox.com to read arbitrary file...

  • EPSS 0.99%
  • Veröffentlicht 11.02.2020 16:15:12
  • Zuletzt bearbeitet 31.03.2025 11:54:18

Zend Framework, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.

  • EPSS 0.25%
  • Veröffentlicht 23.01.2020 20:15:11
  • Zuletzt bearbeitet 31.03.2025 11:54:18

Cross-site request forgery (CSRF) vulnerability in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2 allows remote attackers to hijack the authentication of users for requests that reset passwords via a crafted HTTP Host header.

  • EPSS 0.24%
  • Veröffentlicht 22.11.2019 19:15:11
  • Zuletzt bearbeitet 31.03.2025 11:54:18

Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 4.5.5, 4.0.10, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) unspecified parameters to apps/calendar/ajax/event/new.php or (2) url parameter to ap...

  • EPSS 0.86%
  • Veröffentlicht 26.03.2018 18:29:00
  • Zuletzt bearbeitet 21.11.2024 02:05:32

The user_openid app in ownCloud Server before 5.0.15 allows remote attackers to obtain access by leveraging an insecure OpenID implementation.

Exploit
  • EPSS 0.34%
  • Veröffentlicht 20.03.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 02:04:47

Cross-site scripting (XSS) vulnerability in ownCloud before 6.0.1 allows remote authenticated users to inject arbitrary web script or HTML via the filename of an uploaded file.

  • EPSS 0.38%
  • Veröffentlicht 17.07.2017 21:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

ownCloud Server before 8.2.12, 9.0.x before 9.0.10, 9.1.x before 9.1.6, and 10.0.x before 10.0.2 are vulnerable to XSS on error pages by injecting code in url parameters.

  • EPSS 0.24%
  • Veröffentlicht 17.07.2017 21:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Inadequate escaping lead to XSS vulnerability in the search module in ownCloud Server before 8.2.12, 9.0.x before 9.0.10, 9.1.x before 9.1.6, and 10.0.x before 10.0.2. To be exploitable a user has to write or paste malicious content into the search d...