{"api_version":"1","generated_at":"2026-07-23T04:22:17+00:00","cve":"CVE-2016-9459","urls":{"html":"https://cve.report/CVE-2016-9459","api":"https://cve.report/api/cve/CVE-2016-9459.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2016-9459","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2016-9459"},"summary":{"title":"CVE-2016-9459","description":"Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are vulnerable to a log pollution vulnerability potentially leading to a local XSS. The download log functionality in the admin screen is delivering the log in JSON format to the end-user. The file was delivered with an attachment disposition forcing the browser to download the document. However, Firefox running on Microsoft Windows would offer the user to open the data in the browser as an HTML document. Thus any injected data in the log would be executed.","state":"PUBLISHED","assigner":"hackerone","published_at":"2017-03-28 02:59:00","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-209","CWE-79","CWE-209 Cross-Site Scripting Using MIME Type Mismatch (CWE-209)"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"6.1","severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"https://github.com/owncloud/core/commit/044ee072a647636b1a17c89265c7233b35371335","name":"https://github.com/owncloud/core/commit/044ee072a647636b1a17c89265c7233b35371335","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Patch","Third Party Advisory"],"title":"[stable8.1] Set content type when downloading log file to force downl… · owncloud/core@044ee07 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/97284","name":"http://www.securityfocus.com/bid/97284","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"ownCloud and Nextcloud CVE-2016-9459 HTML Injection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://github.com/owncloud/core/commit/efa35d621dc7ff975468e636a5d1c153511296dc","name":"https://github.com/owncloud/core/commit/efa35d621dc7ff975468e636a5d1c153511296dc","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Patch","Third Party Advisory"],"title":"[stable9] Set content type when downloading log file to force downloa… · owncloud/core@efa35d6 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://owncloud.org/security/advisory?id=oc-sa-2016-012","name":"https://owncloud.org/security/advisory?id=oc-sa-2016-012","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Security Advisories – ownCloud","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"https://nextcloud.com/security/advisory/?id=nc-sa-2016-002","name":"https://nextcloud.com/security/advisory/?id=nc-sa-2016-002","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"advisory – Nextcloud","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://hackerone.com/reports/146278","name":"https://hackerone.com/reports/146278","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"],"title":"HackerOne","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/owncloud/core/commit/b7fa2c5dc945b40bc6ed0a9a0e47c282ebf043e1","name":"https://github.com/owncloud/core/commit/b7fa2c5dc945b40bc6ed0a9a0e47c282ebf043e1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Patch","Third Party Advisory"],"title":"[stable8.2] Set content type when downloading log file to force downl… · owncloud/core@b7fa2c5 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/nextcloud/server/commit/94975af6db1551c2d23136c2ea22866a5b416070","name":"https://github.com/nextcloud/server/commit/94975af6db1551c2d23136c2ea22866a5b416070","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Patch","Third Party Advisory"],"title":"[stable9] Set content-type to \"application/octet-stream\" · nextcloud/server@94975af · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2016-9459","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2016-9459","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"Nextcloud Server & ownCloud Server Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4","version":"affected Nextcloud Server & ownCloud Server Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2016","cve_id":"9459","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"nextcloud","cpe5":"nextcloud_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"9459","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"owncloud","cpe5":"owncloud","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T02:50:38.563Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"https://owncloud.org/security/advisory?id=oc-sa-2016-012"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://github.com/owncloud/core/commit/b7fa2c5dc945b40bc6ed0a9a0e47c282ebf043e1"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://github.com/owncloud/core/commit/044ee072a647636b1a17c89265c7233b35371335"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://hackerone.com/reports/146278"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://github.com/owncloud/core/commit/efa35d621dc7ff975468e636a5d1c153511296dc"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://nextcloud.com/security/advisory/?id=nc-sa-2016-002"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://github.com/nextcloud/server/commit/94975af6db1551c2d23136c2ea22866a5b416070"},{"name":"97284","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/97284"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"Nextcloud Server & ownCloud Server Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4","vendor":"n/a","versions":[{"status":"affected","version":"Nextcloud Server & ownCloud Server Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4"}]}],"datePublic":"2017-03-27T00:00:00.000Z","descriptions":[{"lang":"en","value":"Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are vulnerable to a log pollution vulnerability potentially leading to a local XSS. The download log functionality in the admin screen is delivering the log in JSON format to the end-user. The file was delivered with an attachment disposition forcing the browser to download the document. However, Firefox running on Microsoft Windows would offer the user to open the data in the browser as an HTML document. Thus any injected data in the log would be executed."}],"problemTypes":[{"descriptions":[{"cweId":"CWE-209","description":"Cross-Site Scripting Using MIME Type Mismatch (CWE-209)","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2017-04-03T09:57:01.000Z","orgId":"36234546-b8fa-4601-9d6f-f4e334aa8ea1","shortName":"hackerone"},"references":[{"tags":["x_refsource_MISC"],"url":"https://owncloud.org/security/advisory?id=oc-sa-2016-012"},{"tags":["x_refsource_MISC"],"url":"https://github.com/owncloud/core/commit/b7fa2c5dc945b40bc6ed0a9a0e47c282ebf043e1"},{"tags":["x_refsource_MISC"],"url":"https://github.com/owncloud/core/commit/044ee072a647636b1a17c89265c7233b35371335"},{"tags":["x_refsource_MISC"],"url":"https://hackerone.com/reports/146278"},{"tags":["x_refsource_MISC"],"url":"https://github.com/owncloud/core/commit/efa35d621dc7ff975468e636a5d1c153511296dc"},{"tags":["x_refsource_MISC"],"url":"https://nextcloud.com/security/advisory/?id=nc-sa-2016-002"},{"tags":["x_refsource_MISC"],"url":"https://github.com/nextcloud/server/commit/94975af6db1551c2d23136c2ea22866a5b416070"},{"name":"97284","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/97284"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"support@hackerone.com","ID":"CVE-2016-9459","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Nextcloud Server & ownCloud Server Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4","version":{"version_data":[{"version_value":"Nextcloud Server & ownCloud Server Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are vulnerable to a log pollution vulnerability potentially leading to a local XSS. The download log functionality in the admin screen is delivering the log in JSON format to the end-user. The file was delivered with an attachment disposition forcing the browser to download the document. However, Firefox running on Microsoft Windows would offer the user to open the data in the browser as an HTML document. Thus any injected data in the log would be executed."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Cross-Site Scripting Using MIME Type Mismatch (CWE-209)"}]}]},"references":{"reference_data":[{"name":"https://owncloud.org/security/advisory?id=oc-sa-2016-012","refsource":"MISC","url":"https://owncloud.org/security/advisory?id=oc-sa-2016-012"},{"name":"https://github.com/owncloud/core/commit/b7fa2c5dc945b40bc6ed0a9a0e47c282ebf043e1","refsource":"MISC","url":"https://github.com/owncloud/core/commit/b7fa2c5dc945b40bc6ed0a9a0e47c282ebf043e1"},{"name":"https://github.com/owncloud/core/commit/044ee072a647636b1a17c89265c7233b35371335","refsource":"MISC","url":"https://github.com/owncloud/core/commit/044ee072a647636b1a17c89265c7233b35371335"},{"name":"https://hackerone.com/reports/146278","refsource":"MISC","url":"https://hackerone.com/reports/146278"},{"name":"https://github.com/owncloud/core/commit/efa35d621dc7ff975468e636a5d1c153511296dc","refsource":"MISC","url":"https://github.com/owncloud/core/commit/efa35d621dc7ff975468e636a5d1c153511296dc"},{"name":"https://nextcloud.com/security/advisory/?id=nc-sa-2016-002","refsource":"MISC","url":"https://nextcloud.com/security/advisory/?id=nc-sa-2016-002"},{"name":"https://github.com/nextcloud/server/commit/94975af6db1551c2d23136c2ea22866a5b416070","refsource":"MISC","url":"https://github.com/nextcloud/server/commit/94975af6db1551c2d23136c2ea22866a5b416070"},{"name":"97284","refsource":"BID","url":"http://www.securityfocus.com/bid/97284"}]}}}},"cveMetadata":{"assignerOrgId":"36234546-b8fa-4601-9d6f-f4e334aa8ea1","assignerShortName":"hackerone","cveId":"CVE-2016-9459","datePublished":"2017-03-28T02:46:00.000Z","dateReserved":"2016-11-19T00:00:00.000Z","dateUpdated":"2024-08-06T02:50:38.563Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-03-28 02:59:00","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-209","CWE-79","CWE-209 Cross-Site Scripting Using MIME Type Mismatch (CWE-209)"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:*:*:*:*","versionEndExcluding":"9.0.52","matchCriteriaId":"DC479D9A-DAEB-42B6-98D7-0A417B34359D"},{"vulnerable":true,"criteria":"cpe:2.3:a:owncloud:owncloud:*:*:*:*:*:*:*:*","versionEndExcluding":"9.0.4","matchCriteriaId":"3FAD2663-CE0E-4AB0-90C5-D47124458AAC"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2016","CveId":"9459","Ordinal":"1","Title":"CVE-2016-9459","CVE":"CVE-2016-9459","Year":"2016"},"notes":[{"CveYear":"2016","CveId":"9459","Ordinal":"1","NoteData":"Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are vulnerable to a log pollution vulnerability potentially leading to a local XSS. The download log functionality in the admin screen is delivering the log in JSON format to the end-user. The file was delivered with an attachment disposition forcing the browser to download the document. However, Firefox running on Microsoft Windows would offer the user to open the data in the browser as an HTML document. Thus any injected data in the log would be executed.","Type":"Description","Title":"CVE-2016-9459"},{"CveYear":"2016","CveId":"9459","Ordinal":"2","NoteData":"2017-03-27","Type":"Other","Title":"Published"},{"CveYear":"2016","CveId":"9459","Ordinal":"3","NoteData":"2017-04-03","Type":"Other","Title":"Modified"}]}}}