Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2013-2043

Опубликовано: 14 мар. 2014
Источник: ubuntu
Приоритет: medium
CVSS2: 4

Описание

apps/calendar/ajax/events.php in ownCloud before 4.5.11 and 5.x before 5.0.6 does not properly check the ownership of a calendar, which allows remote authenticated users to download arbitrary calendars via the calendar_id parameter.

РелизСтатусПримечание
devel

not-affected

6.0.1+dfsg-1ubuntu1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected [6.0.1+dfsg-1ubuntu1]]
lucid

DNE

precise

not-affected

quantal

not-affected

4.0.8debian-1.1ubuntu0.1
raring

ignored

end of life
saucy

not-affected

5.0.10+dfsg-1ubuntu1
trusty

not-affected

6.0.1+dfsg-1ubuntu1
trusty/esm

DNE

trusty was not-affected [6.0.1+dfsg-1ubuntu1]
upstream

released

5.0.6

Показывать по

4 Medium

CVSS2

Связанные уязвимости

nvd
почти 12 лет назад

apps/calendar/ajax/events.php in ownCloud before 4.5.11 and 5.x before 5.0.6 does not properly check the ownership of a calendar, which allows remote authenticated users to download arbitrary calendars via the calendar_id parameter.

debian
почти 12 лет назад

apps/calendar/ajax/events.php in ownCloud before 4.5.11 and 5.x before ...

github
больше 3 лет назад

apps/calendar/ajax/events.php in ownCloud before 4.5.11 and 5.x before 5.0.6 does not properly check the ownership of a calendar, which allows remote authenticated users to download arbitrary calendars via the calendar_id parameter.

4 Medium

CVSS2