Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.809415
Kategorie:Web application abuses
Titel:Nextcloud 'share.js' Gallery Application XSS Vulnerability (Linux)
Zusammenfassung:Nextcloud is prone to cross-site scripting (XSS) vulnerability.
Beschreibung:Summary:
Nextcloud is prone to cross-site scripting (XSS) vulnerability.

Vulnerability Insight:
The flaw exists due to a recent migration
of the gallery app to the new sharing endpoint and a parameter changed from an
integer to a string value which is not sanitized properly.

Vulnerability Impact:
Successful exploitation will allow remote
authenticated users to inject arbitrary web script or HTML.

Affected Software/OS:
Nextcloud Server before 9.0.52 on Linux.

Solution:
Upgrade to Nextcloud Server 9.0.52 or later.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:P/A:N

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2016-7419
BugTraq ID: 92373
http://www.securityfocus.com/bid/92373
https://hackerone.com/reports/145355
Common Vulnerability Exposure (CVE) ID: CVE-2016-9459
BugTraq ID: 97284
http://www.securityfocus.com/bid/97284
https://github.com/nextcloud/server/commit/94975af6db1551c2d23136c2ea22866a5b416070
https://github.com/owncloud/core/commit/044ee072a647636b1a17c89265c7233b35371335
https://github.com/owncloud/core/commit/b7fa2c5dc945b40bc6ed0a9a0e47c282ebf043e1
https://github.com/owncloud/core/commit/efa35d621dc7ff975468e636a5d1c153511296dc
https://hackerone.com/reports/146278
https://nextcloud.com/security/advisory/?id=nc-sa-2016-002
https://owncloud.org/security/advisory?id=oc-sa-2016-012
Common Vulnerability Exposure (CVE) ID: CVE-2016-9460
BugTraq ID: 97282
http://www.securityfocus.com/bid/97282
https://github.com/nextcloud/server/commit/2da43e3751576bbc838f238a09955c4dcdebee8e
https://github.com/nextcloud/server/commit/8aa0832bd449c44ec300da4189bd8ed4e036140c
https://github.com/nextcloud/server/commit/dea8e29289a1b99d5e889627c2e377887f4f2983
https://github.com/owncloud/core/commit/c92c234059f8b1dc7d53122985ec0d398895a2cf
https://hackerone.com/reports/145463
https://nextcloud.com/security/advisory/?id=nc-sa-2016-003
https://owncloud.org/security/advisory/?id=oc-sa-2016-013
Common Vulnerability Exposure (CVE) ID: CVE-2016-9461
BugTraq ID: 97276
http://www.securityfocus.com/bid/97276
https://github.com/nextcloud/server/commit/3491400261c1454a9a30d3ec96969573330120cc
https://github.com/owncloud/core/commit/0622e635d97cb17c5e1363e370bb8268cc3d2547
https://github.com/owncloud/core/commit/121a3304a0c37ccda0e1b63ddc528cba9121a36e
https://github.com/owncloud/core/commit/acbbadb71ceee7f01da347f7dcd519beda78cc47
https://github.com/owncloud/core/commit/c0a4b7b3f38ad2eaf506484b3b92ec678cb021c9
https://hackerone.com/reports/145950
https://nextcloud.com/security/advisory/?id=nc-sa-2016-004
https://owncloud.org/security/advisory/?id=oc-sa-2016-014
Common Vulnerability Exposure (CVE) ID: CVE-2016-9462
BugTraq ID: 97285
http://www.securityfocus.com/bid/97285
https://github.com/nextcloud/server/commit/1208953ba1d4d55a18a639846bbcdd66a2d5bc5e
https://github.com/owncloud/core/commit/23383080731d092e079986464a8c4c9ffcb79f4c
https://github.com/owncloud/core/commit/3b056fa68ce502ceb0db9b446dab3b9e7b10dd13
https://github.com/owncloud/core/commit/c93eca49c32428ece03dd67042772d5fa62c8d6e
https://github.com/owncloud/core/commit/d31720b6f1e8c8dfeb5e8805ab35ad7c8000b2f1
https://hackerone.com/reports/146067
https://nextcloud.com/security/advisory/?id=nc-sa-2016-005
https://owncloud.org/security/advisory/?id=oc-sa-2016-015
CopyrightCopyright (C) 2016 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.