Vulnerabilities > Owncloud > Owncloud > 5.0.9

DATE CVE VULNERABILITY TITLE RISK
2016-09-17 CVE-2016-7419 Cross-site Scripting vulnerability in multiple products
Cross-site scripting (XSS) vulnerability in share.js in the gallery application in ownCloud Server before 9.0.4 and Nextcloud Server before 9.0.52 allows remote authenticated users to inject arbitrary web script or HTML via a crafted directory name.
3.5
2016-01-08 CVE-2016-1501 Information Exposure vulnerability in Owncloud
ownCloud Server before 8.0.9 and 8.1.x before 8.1.4 allow remote authenticated users to obtain sensitive information via unspecified vectors, which reveals the installation path in the resulting exception messages.
network
low complexity
owncloud CWE-200
4.0
2016-01-08 CVE-2016-1500 Information Exposure vulnerability in Owncloud
ownCloud Server before 7.0.12, 8.0.x before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2, when the "file_versions" application is enabled, does not properly check the return value of getOwner, which allows remote authenticated users to read the files with names starting with ".v" and belonging to a sharing user by leveraging an incoming share.
network
owncloud CWE-200
3.5
2016-01-08 CVE-2016-1499 Resource Management Errors vulnerability in Owncloud
ownCloud Server before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2 allow remote authenticated users to obtain sensitive information from a directory listing and possibly cause a denial of service (CPU consumption) via the force parameter to index.php/apps/files/ajax/scan.php.
network
low complexity
owncloud CWE-399
7.5
2016-01-08 CVE-2016-1498 Cross-site Scripting vulnerability in Owncloud
Cross-site scripting (XSS) vulnerability in the OCS discovery provider component in ownCloud Server before 7.0.12, 8.0.x before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving a URL.
network
owncloud CWE-79
4.3
2015-10-21 CVE-2015-7698 OS Command Injection vulnerability in Owncloud and SMB
icewind1991 SMB before 1.0.3 allows remote authenticated users to execute arbitrary SMB commands via shell metacharacters in the user argument in the (1) listShares function in Server.php or the (2) connect or (3) read function in Share.php.
network
low complexity
owncloud CWE-78
critical
9.0
2015-10-21 CVE-2015-5954 Unspecified vulnerability in Owncloud
The virtual filesystem in ownCloud Server before 6.0.9, 7.0.x before 7.0.7, and 8.0.x before 8.0.5 does not consider that NULL is a valid getPath return value, which allows remote authenticated users to bypass intended access restrictions and gain access to users files via a sharing link to a file with a deleted parent folder.
network
low complexity
owncloud
4.0
2015-10-21 CVE-2015-4718 OS Command Injection vulnerability in Owncloud
The external SMB storage driver in ownCloud Server before 6.0.8, 7.0.x before 7.0.6, and 8.0.x before 8.0.4 allows remote authenticated users to execute arbitrary SMB commands via a ; (semicolon) character in a file.
network
low complexity
owncloud CWE-78
critical
9.0
2015-10-21 CVE-2015-4717 Resource Management Errors vulnerability in Owncloud
The filename sanitization component in ownCloud Server before 6.0.8, 7.0.x before 7.0.6, and 8.0.x before 8.0.4 does not properly handle $_GET parameters cast by PHP to an array, which allows remote attackers to cause a denial of service (infinite loop and log file consumption) via crafted endpoint file names.
network
low complexity
owncloud CWE-399
7.8
2015-10-21 CVE-2015-4716 Path Traversal vulnerability in multiple products
Directory traversal vulnerability in the routing component in ownCloud Server before 7.0.6 and 8.0.x before 8.0.4, when running on Windows, allows remote attackers to reinstall the application or execute arbitrary code via unspecified vectors.
network
low complexity
owncloud microsoft CWE-22
critical
10.0