257151
|
- |
|
owncloud
|
owncloud
|
Incomplete blacklist vulnerability in ownCloud before 5.0.6 allows remote authenticated users to execute arbitrary PHP code by uploading a crafted file, then accessing it via a direct request to the …
|
NVD-CWE-Other
|
CVE-2013-2089
|
2014-03-18 00:36 |
2014-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257152
|
- |
|
owncloud
|
owncloud
|
Per: https://cwe.mitre.org/data/definitions/184.html
"CWE-184: Incomplete Blacklist"
|
NVD-CWE-Other
|
CVE-2013-2089
|
2014-03-18 00:36 |
2014-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257153
|
- |
|
owncloud
|
owncloud
|
ownCloud before 5.0.6 does not properly check permissions, which allows remote authenticated users to execute arbitrary API commands via unspecified vectors. NOTE: this can be leveraged using CSRF t…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-2048
|
2014-03-18 00:26 |
2014-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257154
|
- |
|
owncloud
|
owncloud
|
Open redirect vulnerability in the Login Page (index.php) in ownCloud before 5.0.6 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redir…
|
CWE-20
Improper Input Validation
|
CVE-2013-2044
|
2014-03-18 00:24 |
2014-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257155
|
- |
|
owncloud
|
owncloud
|
apps/calendar/ajax/events.php in ownCloud before 4.5.11 and 5.x before 5.0.6 does not properly check the ownership of a calendar, which allows remote authenticated users to download arbitrary calenda…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-2043
|
2014-03-18 00:22 |
2014-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257156
|
- |
|
owncloud
|
owncloud
|
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 4.0.15, 4.5.x before 4.5.11, and 5.0.x before 5.0.6 allow remote authenticated users to inject arbitrary web script or HTML via …
|
CWE-79
Cross-site Scripting
|
CVE-2013-2042
|
2014-03-18 00:19 |
2014-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257157
|
- |
|
owncloud
|
owncloud
|
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 5.0.x before 5.0.6 allow remote authenticated users to inject arbitrary web script or HTML via the (1) tag parameter to apps/bookmarks/…
|
CWE-79
Cross-site Scripting
|
CVE-2013-2041
|
2014-03-18 00:17 |
2014-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257158
|
- |
|
owncloud
|
owncloud
|
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 4.0.15, 4.5.x before 4.5.11, and 5.0.x before 5.0.6 allow remote authenticated users to inject arbitrary web script or HTML via …
|
CWE-79
Cross-site Scripting
|
CVE-2013-2040
|
2014-03-18 00:15 |
2014-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257159
|
- |
|
owncloud
|
owncloud
|
Directory traversal vulnerability in lib/files/view.php in ownCloud before 4.0.15, 4.5.x 4.5.11, and 5.x before 5.0.6 allows remote authenticated users to access arbitrary files via unspecified vecto…
|
CWE-22
Path Traversal
|
CVE-2013-2039
|
2014-03-18 00:14 |
2014-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257160
|
- |
|
owncloud
|
owncloud
|
The contacts application in ownCloud before 4.5.10 and 5.x before 5.0.5 does not properly check the ownership of contacts, which allows remote authenticated users to download arbitrary contacts via u…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-1963
|
2014-03-18 00:10 |
2014-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|