ownCloud 'base.php' Arbitrary File Disclosure Vulnerability
BID:68305
Info
ownCloud 'base.php' Arbitrary File Disclosure Vulnerability
| Bugtraq ID: | 68305 |
| Class: | Design Error |
| CVE: |
CVE-2012-5336 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 10 2012 12:00AM |
| Updated: | Aug 10 2012 12:00AM |
| Credit: | Lukas Reschke |
| Vulnerable: |
ownCloud ownCloud 4.0.7 ownCloud ownCloud 4.0.6 ownCloud ownCloud 4.0.5 ownCloud ownCloud 4.0.4 ownCloud ownCloud 4.0.3 ownCloud ownCloud 4.0.2 ownCloud ownCloud 4.0.1 |
| Not Vulnerable: |
ownCloud ownCloud 4.0.8 |
Discussion
ownCloud 'base.php' Arbitrary File Disclosure Vulnerability
ownCloud is prone to an arbitrary file-disclosure vulnerability because it fails to adequately validate user-supplied input.
An attacker could exploit this vulnerability to read arbitrary files on computers running the vulnerable application. This may aid in further attacks.
ownCloud is prone to an arbitrary file-disclosure vulnerability because it fails to adequately validate user-supplied input.
An attacker could exploit this vulnerability to read arbitrary files on computers running the vulnerable application. This may aid in further attacks.
Solution / Fix
ownCloud 'base.php' Arbitrary File Disclosure Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
ownCloud 'base.php' Arbitrary File Disclosure Vulnerability
References:
References:
- ownCloud Homepage (ownCloud)
- Auth bypass in /lib/base.php (oC-SA-2012-011) (ownCloud)