7.5
CVSSv2

CVE-2016-1499

Published: 08/01/2016 Updated: 09/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 7.8 | Exploitability Score: 8
CVSS v3 Base Score: 8.5 | Impact Score: 4.7 | Exploitability Score: 3.1
VMScore: 668
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:C

Vulnerability Summary

ownCloud Server prior to 8.0.10, 8.1.x prior to 8.1.5, and 8.2.x prior to 8.2.2 allow remote authenticated users to obtain sensitive information from a directory listing and possibly cause a denial of service (CPU consumption) via the force parameter to index.php/apps/files/ajax/scan.php.

Vulnerable Product Search on Vulmon Subscribe to Product

owncloud owncloud 8.1.1

owncloud owncloud 8.1.3

owncloud owncloud 8.1.4

owncloud owncloud 8.2.0

owncloud owncloud

owncloud owncloud 8.1.0

owncloud owncloud 8.2.1

Exploits

ownCloud versions 821 and below, 814 and below, and 809 and below suffer from an information exposure vulnerability via directory listings ...