CVE-2012-5336
04.06.2014, 14:55
lib/base.php in ownCloud before 4.0.8 does not properly validate the user_id session variable, which allows remote authenticated users to read arbitrary files via vectors related to WebDAV.Enginsight
Vendor | Product | Version |
---|---|---|
owncloud | owncloud | 𝑥 ≤ 4.0.7 |
owncloud | owncloud_server | 4.0.0 |
owncloud | owncloud_server | 4.0.1 |
owncloud | owncloud_server | 4.0.2 |
owncloud | owncloud_server | 4.0.3 |
owncloud | owncloud_server | 4.0.4 |
owncloud | owncloud_server | 4.0.5 |
owncloud | owncloud_server | 4.0.6 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration