3.5
CVSSv2

CVE-2016-1500

Published: 08/01/2016 Updated: 12/01/2016
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 3.1 | Impact Score: 1.4 | Exploitability Score: 1.6
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:P/I:N/A:N

Vulnerability Summary

ownCloud Server prior to 7.0.12, 8.0.x prior to 8.0.10, 8.1.x prior to 8.1.5, and 8.2.x prior to 8.2.2, when the "file_versions" application is enabled, does not properly check the return value of getOwner, which allows remote authenticated users to read the files with names starting with ".v" and belonging to a sharing user by leveraging an incoming share.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

owncloud owncloud

owncloud owncloud 8.2.1

owncloud owncloud 8.1.0

owncloud owncloud 8.0.9

owncloud owncloud 8.0.8

owncloud owncloud 8.0.6

owncloud owncloud 8.2.0

owncloud owncloud 8.1.3

owncloud owncloud 8.0.4

owncloud owncloud 8.0.2

owncloud owncloud 8.1.4

owncloud owncloud 8.1.1

owncloud owncloud 8.0.5

owncloud owncloud 8.0.3

owncloud owncloud 8.0.0