ownCloud HTML Injection and Authentication Bypass Vulnerabilities
BID:57030
Info
ownCloud HTML Injection and Authentication Bypass Vulnerabilities
| Bugtraq ID: | 57030 |
| Class: | Unknown |
| CVE: |
CVE-2012-5665 CVE-2012-5666 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 20 2012 12:00AM |
| Updated: | Dec 20 2012 12:00AM |
| Credit: | Yuji Kosuga and vendor |
| Vulnerable: |
ownCloud ownCloud 4.5.2 ownCloud ownCloud 4.5 ownCloud ownCloud 4.0.9 ownCloud ownCloud 4.0.7 ownCloud ownCloud 4.0.6 ownCloud ownCloud 4.0.5 ownCloud ownCloud 4.0.4 ownCloud ownCloud 4.0.3 ownCloud ownCloud 4.0.2 ownCloud ownCloud 4.0.1 |
| Not Vulnerable: |
ownCloud ownCloud 4.5.5 ownCloud ownCloud 4.0.10 |
Discussion
ownCloud HTML Injection and Authentication Bypass Vulnerabilities
ownCloud is prone to an HTML-injection and multiple authentication-bypass vulnerabilities.
An attacker may leverage the HTML-injection issue to inject hostile HTML and script code that would run in the context of the affected site, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. The attacker may leverage the authentication-bypass issues to bypass certain security restrictions and perform unauthorized actions in the affected application.
Versions prior to ownCloud 4.5.5 and 4.0.10 are vulnerable.
ownCloud is prone to an HTML-injection and multiple authentication-bypass vulnerabilities.
An attacker may leverage the HTML-injection issue to inject hostile HTML and script code that would run in the context of the affected site, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. The attacker may leverage the authentication-bypass issues to bypass certain security restrictions and perform unauthorized actions in the affected application.
Versions prior to ownCloud 4.5.5 and 4.0.10 are vulnerable.
Exploit / POC
ownCloud HTML Injection and Authentication Bypass Vulnerabilities
An attacker can use a browser to exploit these issues.
An attacker can use a browser to exploit these issues.
Solution / Fix
ownCloud HTML Injection and Authentication Bypass Vulnerabilities
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
ownCloud HTML Injection and Authentication Bypass Vulnerabilities
References:
References:
- Auth bypass in user_webdavauth and user_ldap (oC-SA-2012-006) (ownCloud)
- ownCloud 4.5.5 and 4.0.10 Changelog (ownCloud)
- ownCloud Homepage (ownCloud)
- XSS vulnerability in bookmarks (oC-SA-2012-007) (ownCloud)