ownCloud Bookmarks Application CVE-2014-9041 Cross-Site Request Forgery Vulnerability
BID:71383
Info
ownCloud Bookmarks Application CVE-2014-9041 Cross-Site Request Forgery Vulnerability
| Bugtraq ID: | 71383 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-9041 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 25 2014 12:00AM |
| Updated: | May 07 2015 05:24PM |
| Credit: | Alain Homewood - PwC New Zealand () |
| Vulnerable: |
ownCloud ownCloud 7.0.2 ownCloud ownCloud 7.0.1 ownCloud ownCloud 7.0 ownCloud ownCloud 6.0.4 ownCloud ownCloud 6.0.1 ownCloud ownCloud 5.0.11 ownCloud ownCloud 5.0.10 ownCloud ownCloud 5.0.8 ownCloud ownCloud 5.0.7 ownCloud ownCloud 5.0.6 ownCloud ownCloud 5.0.5 ownCloud ownCloud 5.0.4 ownCloud ownCloud 5.0.3 ownCloud ownCloud 5.0.1 ownCloud ownCloud 5.0 ownCloud ownCloud 6.0.5 ownCloud ownCloud 6.0.3 ownCloud ownCloud 6.0.2 ownCloud ownCloud 6.0.0 ownCloud ownCloud 5.0.9 ownCloud ownCloud 5.0.2 ownCloud ownCloud 5.0.17 ownCloud ownCloud 5.0.16 ownCloud ownCloud 5.0.15 ownCloud ownCloud 5.0.14 ownCloud ownCloud 5.0.13 ownCloud ownCloud 5.0.12 Mandriva Business Server 1 X86 64 Mandriva Business Server 1 |
| Not Vulnerable: |
ownCloud ownCloud 7.0.3 ownCloud ownCloud 6.0.6 ownCloud ownCloud 5.0.18 |
Discussion
ownCloud Bookmarks Application CVE-2014-9041 Cross-Site Request Forgery Vulnerability
ownCloud Bookmarks application is prone to a cross-site request-forgery vulnerability.
Exploiting this issue may allow a remote attacker to perform certain unauthorized actions within the context of the application.
ownCloud Bookmarks application is prone to a cross-site request-forgery vulnerability.
Exploiting this issue may allow a remote attacker to perform certain unauthorized actions within the context of the application.
Exploit / POC
ownCloud Bookmarks Application CVE-2014-9041 Cross-Site Request Forgery Vulnerability
To exploit this issue, an attacker must entice an unsuspecting victim to follow a malicious URI.
To exploit this issue, an attacker must entice an unsuspecting victim to follow a malicious URI.