Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-9044

Опубликовано: 04 фев. 2015
Источник: debian
EPSS Низкий

Описание

Asset Pipeline in ownCloud 7.x before 7.0.3 uses an MD5 hash of the absolute file paths of the original CSS and JS files as the name of the concatenated file, which allows remote attackers to obtain sensitive information via a brute force attack.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
owncloudfixed7.0.3+dfsg-1package

Примечания

  • https://owncloud.org/security/advisory/?id=oc-sa-2014-021

EPSS

Процентиль: 48%
0.0025
Низкий

Связанные уязвимости

nvd
около 11 лет назад

Asset Pipeline in ownCloud 7.x before 7.0.3 uses an MD5 hash of the absolute file paths of the original CSS and JS files as the name of the concatenated file, which allows remote attackers to obtain sensitive information via a brute force attack.

github
больше 3 лет назад

Asset Pipeline in ownCloud 7.x before 7.0.3 uses an MD5 hash of the absolute file paths of the original CSS and JS files as the name of the concatenated file, which allows remote attackers to obtain sensitive information via a brute force attack.

EPSS

Процентиль: 48%
0.0025
Низкий