Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
owncloud owncloud 5.0.5 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2013-2045
SQL injection vulnerability in lib/db.php in ownCloud Server 5.0.x prior to 5.0.6 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
Owncloud Owncloud 5.0.0
Owncloud Owncloud 5.0.2
Owncloud Owncloud 5.0.4
Owncloud Owncloud 5.0.5
Owncloud Owncloud 5.0.1
Owncloud Owncloud 5.0.3
NA
CVE-2013-2041
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 5.0.x prior to 5.0.6 allow remote authenticated users to inject arbitrary web script or HTML via the (1) tag parameter to apps/bookmarks/ajax/addBookmark.php or (2) dir parameter to apps/files/ajax/newfile.php, which...
Owncloud Owncloud 5.0.4
Owncloud Owncloud 5.0.5
Owncloud Owncloud 5.0.1
Owncloud Owncloud 5.0.3
Owncloud Owncloud 5.0.0
Owncloud Owncloud 5.0.2
NA
CVE-2013-2086
The configuration loader in ownCloud 5.0.x prior to 5.0.6 allows remote malicious users to obtain CSRF tokens and other sensitive information by reading an unspecified JavaScript file.
Owncloud Owncloud 5.0.2
Owncloud Owncloud 5.0.3
Owncloud Owncloud 5.0.4
Owncloud Owncloud 5.0.5
Owncloud Owncloud 5.0.0
Owncloud Owncloud 5.0.1
NA
CVE-2013-6403
The admin page in ownCloud prior to 5.0.13 allows remote malicious users to bypass intended access restrictions via unspecified vectors, related to MariaDB.
Owncloud Owncloud 5.0.0
Owncloud Owncloud 5.0.1
Owncloud Owncloud 5.0.7
Owncloud Owncloud 5.0.8
Owncloud Owncloud 5.0.10
Owncloud Owncloud 5.0.2
Owncloud Owncloud 5.0.9
Owncloud Owncloud 5.0.3
Owncloud Owncloud 5.0.4
Owncloud Owncloud
Owncloud Owncloud 5.0.11
Owncloud Owncloud 5.0.5
Owncloud Owncloud 5.0.6
NA
CVE-2013-2046
SQL injection vulnerability in lib/bookmarks.php in ownCloud Server 4.5.x prior to 4.5.11 and 5.x prior to 5.0.6 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
Owncloud Owncloud 4.5.6
Owncloud Owncloud 4.5.7
Owncloud Owncloud 4.5.8
Owncloud Owncloud 4.5.9
Owncloud Owncloud 4.5.3
Owncloud Owncloud 4.5.5
Owncloud Owncloud 4.5.0
Owncloud Owncloud 4.5.1
Owncloud Owncloud 4.5.10
Owncloud Owncloud 4.5.2
Owncloud Owncloud 4.5.4
Owncloud Owncloud 5.0.1
Owncloud Owncloud 5.0.3
Owncloud Owncloud 5.0.4
Owncloud Owncloud 5.0.5
Owncloud Owncloud 5.0.0
Owncloud Owncloud 5.0.2
NA
CVE-2013-2043
apps/calendar/ajax/events.php in ownCloud prior to 4.5.11 and 5.x prior to 5.0.6 does not properly check the ownership of a calendar, which allows remote authenticated users to download arbitrary calendars via the calendar_id parameter.
Owncloud Owncloud 4.5.0
Owncloud Owncloud 5.0.0
Owncloud Owncloud 4.5.8
Owncloud Owncloud 4.5.9
Owncloud Owncloud 5.0.2
Owncloud Owncloud 5.0.4
Owncloud Owncloud 4.5.5
Owncloud Owncloud 4.5.7
Owncloud Owncloud 4.5.1
Owncloud Owncloud
Owncloud Owncloud 4.5.2
Owncloud Owncloud 4.5.3
Owncloud Owncloud 5.0.1
Owncloud Owncloud 5.0.3
Owncloud Owncloud 5.0.5
Owncloud Owncloud 4.5.4
Owncloud Owncloud 4.5.6
NA
CVE-2014-2051
ownCloud Server prior to 5.0.15 and 6.0.x prior to 6.0.2 allows remote malicious users to conduct an LDAP injection attack via unspecified vectors, as demonstrated using a "login query."
Owncloud Owncloud 6.0.0
Owncloud Owncloud 6.0.1
Owncloud Owncloud
Owncloud Owncloud 5.0.14
Owncloud Owncloud 5.0.13
Owncloud Owncloud 5.0.11
Owncloud Owncloud 5.0.1
Owncloud Owncloud 5.0.5
Owncloud Owncloud 5.0.7
Owncloud Owncloud 5.0.9
Owncloud Owncloud 5.0.0
Owncloud Owncloud 5.0.2
Owncloud Owncloud 5.0.3
Owncloud Owncloud 5.0.4
Owncloud Owncloud 5.0.12
Owncloud Owncloud 5.0.10
Owncloud Owncloud 5.0.6
Owncloud Owncloud 5.0.8
NA
CVE-2014-2585
ownCloud prior to 5.0.15 and 6.x prior to 6.0.2, when the file_external app is enabled, allows remote authenticated users to mount the local filesystem in the user's ownCloud via the mount configuration.
Owncloud Owncloud 6.0.0
Owncloud Owncloud 6.0.1
Owncloud Owncloud 5.0.0
Owncloud Owncloud 5.0.1
Owncloud Owncloud 5.0.9
Owncloud Owncloud 5.0.14
Owncloud Owncloud
Owncloud Owncloud 5.0.2
Owncloud Owncloud 5.0.3
Owncloud Owncloud 5.0.11
Owncloud Owncloud 5.0.13
Owncloud Owncloud 5.0.4
Owncloud Owncloud 5.0.6
Owncloud Owncloud 5.0.8
Owncloud Owncloud 5.0.10
Owncloud Owncloud 5.0.12
Owncloud Owncloud 5.0.5
Owncloud Owncloud 5.0.7
NA
CVE-2014-2056
PHPDocX, as used in ownCloud Server prior to 5.0.15 and 6.0.x prior to 6.0.2, allows remote malicious users to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.
Owncloud Owncloud 5.0.13
Owncloud Owncloud
Owncloud Owncloud 5.0.6
Owncloud Owncloud 5.0.8
Owncloud Owncloud 5.0.0
Owncloud Owncloud 5.0.1
Owncloud Owncloud 5.0.10
Owncloud Owncloud 5.0.11
Owncloud Owncloud 5.0.2
Owncloud Owncloud 5.0.3
Owncloud Owncloud 5.0.4
Owncloud Owncloud 5.0.5
Phpdocx Phpdocx -
Owncloud Owncloud 5.0.12
Owncloud Owncloud 5.0.14
Owncloud Owncloud 5.0.7
Owncloud Owncloud 5.0.9
Owncloud Owncloud 6.0.0
Owncloud Owncloud 6.0.1
NA
CVE-2014-3838
ownCloud Server prior to 5.0.16 and 6.0.x prior to 6.0.3 does not properly check permissions, which allows remote authenticated users to read the names of files of other users by leveraging access to multiple accounts.
Owncloud Owncloud 5.0.0
Owncloud Owncloud 5.0.1
Owncloud Owncloud 5.0.10
Owncloud Owncloud 5.0.8
Owncloud Owncloud 5.0.9
Owncloud Owncloud 5.0.12
Owncloud Owncloud 5.0.14
Owncloud Owncloud 5.0.4
Owncloud Owncloud 5.0.6
Owncloud Owncloud
Owncloud Owncloud 5.0.2
Owncloud Owncloud 5.0.3
Owncloud Owncloud 5.0.11
Owncloud Owncloud 5.0.13
Owncloud Owncloud 5.0.5
Owncloud Owncloud 5.0.7
Owncloud Owncloud 6.0.0
Owncloud Owncloud 6.0.1
Owncloud Owncloud 6.0.2
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-21991
CVE-2024-32674
path traversal
CVE-2023-21987
denial of service
dos
CVE-2024-4647
CVE-2024-25519
CVE-2024-33612
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
NEXT »