ownCloud Multiple Security Vulnerabilities
BID:54998
Info
ownCloud Multiple Security Vulnerabilities
| Bugtraq ID: | 54998 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 14 2012 12:00AM |
| Updated: | Aug 14 2012 12:00AM |
| Credit: | Reported by the vendor. |
| Vulnerable: |
ownCloud ownCloud 3.0.2 ownCloud ownCloud 3.0.1 ownCloud ownCloud 3.0.0 |
| Not Vulnerable: | |
Discussion
ownCloud Multiple Security Vulnerabilities
ownCloud is prone to an unspecified cross-site scripting vulnerability, a security-bypass vulnerability, and multiple HTML-injection vulnerabilities.
An attacker can exploit these issues to execute HTML and arbitrary script code in the context of the vulnerable site, potentially allowing the attacker to steal cookie-based authentication credentials or bypass security restrictions to obtain sensitive information, or perform unauthorized actions. Other attacks may also be possible.
Versions prior to ownCloud 4.0.6 are vulnerable.
ownCloud is prone to an unspecified cross-site scripting vulnerability, a security-bypass vulnerability, and multiple HTML-injection vulnerabilities.
An attacker can exploit these issues to execute HTML and arbitrary script code in the context of the vulnerable site, potentially allowing the attacker to steal cookie-based authentication credentials or bypass security restrictions to obtain sensitive information, or perform unauthorized actions. Other attacks may also be possible.
Versions prior to ownCloud 4.0.6 are vulnerable.
Exploit / POC
ownCloud Multiple Security Vulnerabilities
An attacker can use a browser to exploit these issues. To exploit cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
An attacker can use a browser to exploit these issues. To exploit cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
Solution / Fix
ownCloud Multiple Security Vulnerabilities
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.