Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-6670

Опубликовано: 26 окт. 2015
Источник: debian

Описание

ownCloud Server before 7.0.8, 8.0.x before 8.0.6, and 8.1.x before 8.1.1 does not properly check ownership of calendars, which allows remote authenticated users to read arbitrary calendars via the calid parameter to apps/calendar/export.php.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
owncloudfixed7.0.8~dfsg-1package
owncloud-calendarfixed0.7.3-1experimentalpackage

Примечания

  • https://owncloud.org/security/advisory/?id=oc-sa-2015-015

  • https://github.com/owncloud/calendar/commit/4e0306adb13b19919e90857eaf7681303cd45414

Связанные уязвимости

ubuntu
больше 10 лет назад

ownCloud Server before 7.0.8, 8.0.x before 8.0.6, and 8.1.x before 8.1.1 does not properly check ownership of calendars, which allows remote authenticated users to read arbitrary calendars via the calid parameter to apps/calendar/export.php.

nvd
больше 10 лет назад

ownCloud Server before 7.0.8, 8.0.x before 8.0.6, and 8.1.x before 8.1.1 does not properly check ownership of calendars, which allows remote authenticated users to read arbitrary calendars via the calid parameter to apps/calendar/export.php.

github
больше 3 лет назад

ownCloud Server before 7.0.8, 8.0.x before 8.0.6, and 8.1.x before 8.1.1 does not properly check ownership of calendars, which allows remote authenticated users to read arbitrary calendars via the calid parameter to apps/calendar/export.php.

fstec
больше 10 лет назад

Уязвимость веб-приложения для синхронизации данных ownCloud, позволяющая нарушителю читать данные произвольных календарей