Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
owncloud owncloud 4.5.3 vulnerabilities and exploits
(subscribe to this query)
4.6
CVSSv2
CVE-2013-0204
settings/personal.php in ownCloud 4.5.x prior to 4.5.6 allows remote authenticated users to execute arbitrary PHP code via crafted mount point settings.
Owncloud Owncloud 4.5.1
Owncloud Owncloud 4.5.3
Owncloud Owncloud 4.5.5
Owncloud Owncloud 4.5.0
Owncloud Owncloud 4.5.2
Owncloud Owncloud 4.5.4
4
CVSSv2
CVE-2013-0304
ownCloud Server prior to 4.5.7 does not properly check ownership of calendars, which allows remote authenticated users to read arbitrary calendars via the calid parameter to /apps/calendar/export.php. NOTE: this issue has been reported as a cross-site request forgery (CSRF) vulne...
Owncloud Owncloud 4.5.5
Owncloud Owncloud 4.5.3
Owncloud Owncloud 4.5.2
Owncloud Owncloud 4.5.1
Owncloud Owncloud 4.5.0
Owncloud Owncloud
Owncloud Owncloud 4.5.4
4.3
CVSSv2
CVE-2013-0298
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 4.5.x prior to 4.5.7 allow remote malicious users to inject arbitrary web script or HTML via (1) a crafted iCalendar file to the calendar application, the (2) dir or (3) file parameter to apps/files_pdfviewer/viewer....
Owncloud Owncloud 4.5.1
Owncloud Owncloud 4.5.6
Owncloud Owncloud 4.5.2
Owncloud Owncloud 4.5.3
Owncloud Owncloud 4.5.4
Owncloud Owncloud 4.5.5
Owncloud Owncloud 4.5.0
6.8
CVSSv2
CVE-2013-0300
Multiple cross-site request forgery (CSRF) vulnerabilities in ownCloud 4.5.x prior to 4.5.7 allow remote malicious users to hijack the authentication of users for requests that (1) change the default view via the v parameter to apps/calendar/ajax/changeview.php, mount arbitrary (...
Owncloud Owncloud 4.5.0
Owncloud Owncloud 4.5.2
Owncloud Owncloud 4.5.3
Owncloud Owncloud 4.5.4
Owncloud Owncloud 4.5.5
Owncloud Owncloud 4.5.1
Owncloud Owncloud 4.5.6
2.1
CVSSv2
CVE-2013-1822
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 4.5.x prior to 4.5.8 allow remote authenticated users with administrator privileges to inject arbitrary web script or HTML via the (1) quota parameter to /core/settings/ajax/setquota.php, or remote authenticated user...
Owncloud Owncloud 4.5.0
Owncloud Owncloud 4.5.7
Owncloud Owncloud 4.5.1
Owncloud Owncloud 4.5.2
Owncloud Owncloud 4.5.3
Owncloud Owncloud 4.5.4
Owncloud Owncloud 4.5.5
Owncloud Owncloud 4.5.6
4.3
CVSSv2
CVE-2012-5665
ownCloud 4.0.x prior to 4.0.10 and 4.5.x prior to 4.5.5 does not properly restrict access to settings.php, which allows remote malicious users to edit app configurations of user_webdavauth and user_ldap by editing this file.
Owncloud Owncloud 4.0.4
Owncloud Owncloud 4.0.5
Owncloud Owncloud 4.0.6
Owncloud Owncloud 4.0.7
Owncloud Owncloud 4.0.9
Owncloud Owncloud 4.0.1
Owncloud Owncloud 4.0.8
Owncloud Owncloud 4.0.0
Owncloud Owncloud 4.0.2
Owncloud Owncloud 4.0.3
Owncloud Owncloud 4.5.2
Owncloud Owncloud 4.5.1
Owncloud Owncloud 4.5.4
Owncloud Owncloud 4.5.3
Owncloud Owncloud 4.5.0
4.3
CVSSv2
CVE-2012-5666
Cross-site scripting (XSS) vulnerability in bookmarks/js/bookmarks.js in ownCloud 4.0.x prior to 4.0.10 and 4.5.x prior to 4.5.5 allows remote malicious users to inject arbitrary web script or HTML via the PATH_INFO to apps/bookmark/index.php.
Owncloud Owncloud 4.0.8
Owncloud Owncloud 4.0.0
Owncloud Owncloud 4.0.9
Owncloud Owncloud 4.0.1
Owncloud Owncloud 4.0.5
Owncloud Owncloud 4.0.3
Owncloud Owncloud 4.0.6
Owncloud Owncloud 4.0.7
Owncloud Owncloud 4.0.4
Owncloud Owncloud 4.0.2
Owncloud Owncloud 4.5.4
Owncloud Owncloud 4.5.0
Owncloud Owncloud 4.5.1
Owncloud Owncloud 4.5.2
Owncloud Owncloud 4.5.3
4
CVSSv2
CVE-2013-1963
The contacts application in ownCloud prior to 4.5.10 and 5.x prior to 5.0.5 does not properly check the ownership of contacts, which allows remote authenticated users to download arbitrary contacts via unspecified vectors.
Owncloud Owncloud 5.0.0
Owncloud Owncloud 5.0.1
Owncloud Owncloud 5.0.2
Owncloud Owncloud 5.0.3
Owncloud Owncloud 5.0.4
Owncloud Owncloud 4.5.2
Owncloud Owncloud 4.5.4
Owncloud Owncloud
Owncloud Owncloud 4.5.5
Owncloud Owncloud 4.5.6
Owncloud Owncloud 4.5.7
Owncloud Owncloud 4.5.8
Owncloud Owncloud 4.5.1
Owncloud Owncloud 4.5.3
Owncloud Owncloud 4.5.0
4
CVSSv2
CVE-2013-2043
apps/calendar/ajax/events.php in ownCloud prior to 4.5.11 and 5.x prior to 5.0.6 does not properly check the ownership of a calendar, which allows remote authenticated users to download arbitrary calendars via the calendar_id parameter.
Owncloud Owncloud 4.5.0
Owncloud Owncloud 5.0.0
Owncloud Owncloud 4.5.8
Owncloud Owncloud 4.5.9
Owncloud Owncloud 5.0.2
Owncloud Owncloud 5.0.4
Owncloud Owncloud 4.5.5
Owncloud Owncloud 4.5.7
Owncloud Owncloud 4.5.1
Owncloud Owncloud
Owncloud Owncloud 4.5.2
Owncloud Owncloud 4.5.3
Owncloud Owncloud 5.0.1
Owncloud Owncloud 5.0.3
Owncloud Owncloud 5.0.5
Owncloud Owncloud 4.5.4
Owncloud Owncloud 4.5.6
6.5
CVSSv2
CVE-2013-2046
SQL injection vulnerability in lib/bookmarks.php in ownCloud Server 4.5.x prior to 4.5.11 and 5.x prior to 5.0.6 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
Owncloud Owncloud 4.5.6
Owncloud Owncloud 4.5.7
Owncloud Owncloud 4.5.8
Owncloud Owncloud 4.5.9
Owncloud Owncloud 4.5.3
Owncloud Owncloud 4.5.5
Owncloud Owncloud 4.5.0
Owncloud Owncloud 4.5.1
Owncloud Owncloud 4.5.10
Owncloud Owncloud 4.5.2
Owncloud Owncloud 4.5.4
Owncloud Owncloud 5.0.1
Owncloud Owncloud 5.0.3
Owncloud Owncloud 5.0.4
Owncloud Owncloud 5.0.5
Owncloud Owncloud 5.0.0
Owncloud Owncloud 5.0.2
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2022-48654
CVE-2024-2757
authentication bypass
CVE-2024-3194
CVE-2024-33640
CVE-2024-21111
dos
insecure direct object reference
CVE-2024-21345
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »