Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-9041

Опубликовано: 04 фев. 2015
Источник: debian
EPSS Низкий

Описание

The import functionality in the bookmarks application in ownCloud server before 5.0.18, 6.x before 6.0.6, and 7.x before 7.0.3 does not validate CSRF tokens, which allow remote attackers to conduct CSRF attacks.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
owncloudfixed7.0.3+dfsg-1package

Примечания

  • https://owncloud.org/security/advisory/?id=oc-sa-2014-019

EPSS

Процентиль: 40%
0.00182
Низкий

Связанные уязвимости

nvd
около 11 лет назад

The import functionality in the bookmarks application in ownCloud server before 5.0.18, 6.x before 6.0.6, and 7.x before 7.0.3 does not validate CSRF tokens, which allow remote attackers to conduct CSRF attacks.

github
больше 3 лет назад

The import functionality in the bookmarks application in ownCloud server before 5.0.18, 6.x before 6.0.6, and 7.x before 7.0.3 does not validate CSRF tokens, which allow remote attackers to conduct CSRF attacks.

EPSS

Процентиль: 40%
0.00182
Низкий