| Vulnerability Name: | CVE-2016-9460 (CCN-123936) | ||||||||||||
| Assigned: | 2016-10-10 | ||||||||||||
| Published: | 2016-10-10 | ||||||||||||
| Updated: | 2017-04-04 | ||||||||||||
| Summary: | Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are vulnerable to a content-spoofing attack in the files app. The location bar in the files app was not verifying the passed parameters. An attacker could craft an invalid link to a fake directory structure and use this to display an attacker-controlled error message to the user. | ||||||||||||
| CVSS v3 Severity: | 5.3 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N) 4.6 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
| ||||||||||||
| CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
| ||||||||||||
| Vulnerability Type: | CWE-284 | ||||||||||||
| Vulnerability Consequences: | Gain Access | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2016-9460 Source: BID Type: UNKNOWN 97282 Source: CCN Type: BID-97282 ownCloud and NextCloud CVE-2016-9460 Content Spoofing Vulnerability Source: XF Type: UNKNOWN nextcloud-owncloud-cve20169460-spoofing(123936) Source: MISC Type: Issue Tracking, Patch, Third Party Advisory https://github.com/nextcloud/server/commit/2da43e3751576bbc838f238a09955c4dcdebee8e Source: MISC Type: Issue Tracking, Patch, Third Party Advisory https://github.com/nextcloud/server/commit/8aa0832bd449c44ec300da4189bd8ed4e036140c Source: MISC Type: Issue Tracking, Patch, Third Party Advisory https://github.com/nextcloud/server/commit/dea8e29289a1b99d5e889627c2e377887f4f2983 Source: MISC Type: Issue Tracking, Patch, Third Party Advisory https://github.com/owncloud/core/commit/c92c234059f8b1dc7d53122985ec0d398895a2cf Source: MISC Type: Exploit, Third Party Advisory https://hackerone.com/reports/145463 Source: CCN Type: nextCloud Security Advisory NC-SA-2016-003 Content-Spoofing in "files" app Source: MISC Type: Patch, Vendor Advisory https://nextcloud.com/security/advisory/?id=nc-sa-2016-003 Source: CCN Type: ownCloud Security Advisory oC-SA-2016-013 Content-Spoofing in "files" app Source: MISC Type: Patch, Vendor Advisory https://owncloud.org/security/advisory/?id=oc-sa-2016-013 Source: CCN Type: WhiteSource Vulnerability Database CVE-2016-9460 | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
| Oval Definitions | |||||||||||||
| |||||||||||||
| BACK | |||||||||||||