258571
|
- |
|
owncloud
|
owncloud
|
Multiple incomplete blacklist vulnerabilities in (1) import.php and (2) ajax/uploadimport.php in apps/contacts/ in ownCloud before 4.0.13 and 4.5.x before 4.5.8 allow remote authenticated users to ex…
|
CWE-94
Code Injection
|
CVE-2013-1850
|
2014-03-26 06:04 |
2014-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258572
|
- |
|
owncloud
|
owncloud
|
Multiple cross-site scripting (XSS) vulnerabilities in js/viewer.js in ownCloud before 4.5.12 and 5.x before 5.0.7 allow remote attackers to inject arbitrary web script or HTML via vectors related to…
|
CWE-79
Cross-site Scripting
|
CVE-2013-2150
|
2014-03-26 06:03 |
2014-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258573
|
- |
|
owncloud
|
owncloud
|
Per: http://owncloud.org/about/security/advisories/oC-SA-2013-028/
"Cross-site scripting (XSS) vulnerabilities in js/viewer.js inside the files_videoviewer application via multiple unspecified vecto…
|
CWE-79
Cross-site Scripting
|
CVE-2013-2150
|
2014-03-26 06:03 |
2014-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258574
|
- |
|
owncloud
|
owncloud
|
Cross-site request forgery (CSRF) vulnerability in apps/calendar/ajax/settings/settimezone in ownCloud before 4.0.12 allows remote attackers to hijack the authentication of users for requests that ch…
|
CWE-352
Origin Validation Error
|
CVE-2013-0301
|
2014-03-26 05:56 |
2014-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258575
|
- |
|
owncloud
|
owncloud
|
Multiple cross-site request forgery (CSRF) vulnerabilities in ownCloud 4.5.x before 4.5.7 allow remote attackers to hijack the authentication of users for requests that (1) change the default view vi…
|
CWE-352
Origin Validation Error
|
CVE-2013-0300
|
2014-03-26 05:55 |
2014-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258576
|
- |
|
owncloud
|
owncloud
|
Multiple cross-site request forgery (CSRF) vulnerabilities in ownCloud before 4.0.12 and 4.5.x before 4.5.7 allow remote attackers to hijack the authentication of users for requests that (1) change t…
|
CWE-352
Origin Validation Error
|
CVE-2013-0299
|
2014-03-26 05:49 |
2014-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258577
|
- |
|
owncloud
|
owncloud
|
Session fixation vulnerability in ownCloud before 6.0.2, when PHP is configured to accept session parameters through a GET request, allows remote attackers to hijack web sessions via unspecified vect…
|
CWE-287
Improper Authentication
|
CVE-2014-2047
|
2014-03-26 04:36 |
2014-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258578
|
- |
|
owncloud
|
owncloud
|
The default Flash Cross Domain policies in ownCloud before 5.0.15 and 6.x before 6.0.2 allows remote attackers to access user files via unspecified vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-2049
|
2014-03-26 04:32 |
2014-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258579
|
- |
|
open-xchange
|
open-xchange_appsuite
|
Cross-site scripting (XSS) vulnerability in the frontend in Open-Xchange (OX) AppSuite 7.4.1 before 7.4.1-rev10 and 7.4.2 before 7.4.2-rev8 allows remote attackers to inject arbitrary web script or H…
|
CWE-79
Cross-site Scripting
|
CVE-2014-2077
|
2014-03-25 07:55 |
2014-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258580
|
- |
|
cisco
|
webex_meeting_center
|
WebEx Meeting Center in Cisco WebEx Business Suite does not properly compose URLs for HTTP GET requests, which allows remote attackers to obtain sensitive information by reading (1) web-server access…
|
CWE-200
Information Exposure
|
CVE-2014-0708
|
2014-03-25 07:48 |
2014-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|