Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2012-4393

Overview

Vulnerability Score 6.8 6.8
CVE Id CVE-2012-4393
Last Modified 11 Oct 2013 10:10:37
Published 05 Sep 2012 07:55:02
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2012-4393

Summary

Multiple cross-site request forgery (CSRF) vulnerabilities in ownCloud before 4.0.6 allow remote attackers to hijack the authentication of arbitrary users for requests that use (1) addBookmark.php, (2) delBookmark.php, or (3) editBookmark.php in bookmarks/ajax/; (4) calendar/delete.php, (5) calendar/edit.php, (6) calendar/new.php, (7) calendar/update.php, (8) event/delete.php, (9) event/edit.php, (10) event/move.php, (11) event/new.php, (12) import/import.php, (13) settings/setfirstday.php, (14) settings/settimeformat.php, (15) share/changepermission.php, (16) share/share.php, (17) or share/unshare.php in calendar/ajax/; (18) external/ajax/setsites.php, (19) files/ajax/delete.php, (20) files/ajax/move.php, (21) files/ajax/newfile.php, (22) files/ajax/newfolder.php, (23) files/ajax/rename.php, (24) files_sharing/ajax/email.php, (25) files_sharing/ajax/setpermissions.php, (26) files_sharing/ajax/share.php, (27) files_sharing/ajax/toggleresharing.php, (28) files_sharing/ajax/togglesharewitheveryone.php, (29) files_sharing/ajax/unshare.php, (30) files_texteditor/ajax/savefile.php, (31) files_versions/ajax/rollbackVersion.php, (32) gallery/ajax/createAlbum.php, (33) gallery/ajax/sharing.php, (34) tasks/ajax/addtask.php, (35) tasks/ajax/addtaskform.php, (36) tasks/ajax/delete.php, or (37) tasks/ajax/edittask.php in apps/; or administrators for requests that use (38) changepassword.php, (39) creategroup.php, (40) createuser.php, (41) disableapp.php, (42) enableapp.php, (43) lostpassword.php, (44) removegroup.php, (45) removeuser.php, (46) setlanguage.php, (47) setloglevel.php, (48) setquota.php, or (49) togglegroups.php in settings/ajax/.

Vulnerable Systems

Application

  • Owncloud 3.0.0

  • Owncloud 3.0.1

  • Owncloud 3.0.2

  • Owncloud 3.0.3

  • Owncloud 4.0.0

  • Owncloud 4.0.1

  • Owncloud 4.0.2

  • Owncloud 4.0.3

  • Owncloud 4.0.4

  • Owncloud 4.0.5


References

CONFIRM - https://github.com/owncloud/core/commit/93579d88dcea389205c01ddf6da41f37ad9b8745

CONFIRM - https://github.com/owncloud/core/commit/38271ded753bc9ea9943cef3c2706f8d71f3a58f

MLIST - [oss-security] 20120901 Re: CVE - ownCloud

MLIST - [oss-security] 20120810 ownCloud - matching CVEs to fix information and vice versa

CONFIRM - http://owncloud.org/changelog/


Last Updated: 27 May 2016 11:00:29