5.4
CVSSv3

CVE-2014-1665

Published: 20/03/2018 Updated: 13/04/2018
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 355
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in ownCloud prior to 6.0.1 allows remote authenticated users to inject arbitrary web script or HTML via the filename of an uploaded file.

Vulnerable Product Search on Vulmon Subscribe to Product

owncloud owncloud

Exploits

# Exploit Title: ownCloud 600a File Deletion XSS and CSRF Protection Bypass # Vendor Homepage: wwwownCloudorg # OwnCloud Version: 600a # Browsers tested: Iceweasel 220; Internet Explorer 11; # Server: Debian Default LAMP set-up # Exploit Author: James Sibley (absane) # Blog: blognoobrootcom # D ...
ownCloud version 600a suffers from file deletion, cross site request forgery, and cross site scripting vulnerabilities It has also been reported that the same cross site scripting issue also affects Pydio version 520 ...