Back to search
CVE-2016-9468
Published: Mar 28, 2017
Modified: Aug 6, 2024
PUBLISHED
Description
Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the dav app. The exception message displayed on the DAV endpoints contained partially user-controllable input leading to a potential misrepresentation of information.
| Vendor | Product | Versions |
|---|---|---|
n/a | Nextcloud Server & ownCloud Server Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 | affected Nextcloud Server & ownCloud Server Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 |
Weaknesses (CWE)
References
https://owncloud.org/security/advisory/?id=oc-sa-2016-021
x_refsource_MISC
https://hackerone.com/reports/149798
x_refsource_MISC
https://nextcloud.com/security/advisory/?id=nc-sa-2016-011
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now