4
CVSSv2

CVE-2012-5336

Published: 04/06/2014 Updated: 04/06/2014
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

lib/base.php in ownCloud prior to 4.0.8 does not properly validate the user_id session variable, which allows remote authenticated users to read arbitrary files via vectors related to WebDAV.

Vulnerable Product Search on Vulmon Subscribe to Product

owncloud owncloud 4.0.6

owncloud owncloud 4.0.4

owncloud owncloud 4.0.2

owncloud owncloud 4.0.1

owncloud owncloud 4.0.0

owncloud owncloud

owncloud owncloud 4.0.5

owncloud owncloud 4.0.3