Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.809415
Categoría:Web application abuses
Título:Nextcloud 'share.js' Gallery Application XSS Vulnerability - Linux
Resumen:Nextcloud is prone to a cross-site scripting (XSS) vulnerability.
Descripción:Summary:
Nextcloud is prone to a cross-site scripting (XSS) vulnerability.

Vulnerability Insight:
The flaw exists due to a recent migration
of the gallery app to the new sharing endpoint and a parameter changed from an
integer to a string value which is not sanitized properly.

Vulnerability Impact:
Successful exploitation will allow remote
authenticated users to inject arbitrary web script or HTML.

Affected Software/OS:
Nextcloud Server before 9.0.52 on Linux.

Solution:
Upgrade to Nextcloud Server 9.0.52 or later.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:P/A:N

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2016-7419
BugTraq ID: 92373
http://www.securityfocus.com/bid/92373
https://hackerone.com/reports/145355
Common Vulnerability Exposure (CVE) ID: CVE-2016-9459
BugTraq ID: 97284
http://www.securityfocus.com/bid/97284
https://github.com/nextcloud/server/commit/94975af6db1551c2d23136c2ea22866a5b416070
https://github.com/owncloud/core/commit/044ee072a647636b1a17c89265c7233b35371335
https://github.com/owncloud/core/commit/b7fa2c5dc945b40bc6ed0a9a0e47c282ebf043e1
https://github.com/owncloud/core/commit/efa35d621dc7ff975468e636a5d1c153511296dc
https://hackerone.com/reports/146278
https://nextcloud.com/security/advisory/?id=nc-sa-2016-002
https://owncloud.org/security/advisory?id=oc-sa-2016-012
Common Vulnerability Exposure (CVE) ID: CVE-2016-9460
BugTraq ID: 97282
http://www.securityfocus.com/bid/97282
https://github.com/nextcloud/server/commit/2da43e3751576bbc838f238a09955c4dcdebee8e
https://github.com/nextcloud/server/commit/8aa0832bd449c44ec300da4189bd8ed4e036140c
https://github.com/nextcloud/server/commit/dea8e29289a1b99d5e889627c2e377887f4f2983
https://github.com/owncloud/core/commit/c92c234059f8b1dc7d53122985ec0d398895a2cf
https://hackerone.com/reports/145463
https://nextcloud.com/security/advisory/?id=nc-sa-2016-003
https://owncloud.org/security/advisory/?id=oc-sa-2016-013
Common Vulnerability Exposure (CVE) ID: CVE-2016-9461
BugTraq ID: 97276
http://www.securityfocus.com/bid/97276
https://github.com/nextcloud/server/commit/3491400261c1454a9a30d3ec96969573330120cc
https://github.com/owncloud/core/commit/0622e635d97cb17c5e1363e370bb8268cc3d2547
https://github.com/owncloud/core/commit/121a3304a0c37ccda0e1b63ddc528cba9121a36e
https://github.com/owncloud/core/commit/acbbadb71ceee7f01da347f7dcd519beda78cc47
https://github.com/owncloud/core/commit/c0a4b7b3f38ad2eaf506484b3b92ec678cb021c9
https://hackerone.com/reports/145950
https://nextcloud.com/security/advisory/?id=nc-sa-2016-004
https://owncloud.org/security/advisory/?id=oc-sa-2016-014
Common Vulnerability Exposure (CVE) ID: CVE-2016-9462
BugTraq ID: 97285
http://www.securityfocus.com/bid/97285
https://github.com/nextcloud/server/commit/1208953ba1d4d55a18a639846bbcdd66a2d5bc5e
https://github.com/owncloud/core/commit/23383080731d092e079986464a8c4c9ffcb79f4c
https://github.com/owncloud/core/commit/3b056fa68ce502ceb0db9b446dab3b9e7b10dd13
https://github.com/owncloud/core/commit/c93eca49c32428ece03dd67042772d5fa62c8d6e
https://github.com/owncloud/core/commit/d31720b6f1e8c8dfeb5e8805ab35ad7c8000b2f1
https://hackerone.com/reports/146067
https://nextcloud.com/security/advisory/?id=nc-sa-2016-005
https://owncloud.org/security/advisory/?id=oc-sa-2016-015
CopyrightCopyright (C) 2016 Greenbone AG

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.