[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[FD] Several unpatched vulns in OwnCloud
- To: "fulldisclosure@xxxxxxxxxxxx" <fulldisclosure@xxxxxxxxxxxx>
- Subject: [FD] Several unpatched vulns in OwnCloud
- From: Felix Matei <Felix.Matei@xxxxxxxxxxxxxx>
- Date: Mon, 07 Nov 2016 05:13:41 -0500
Dear Community
By comparing the advisory of NextCloud and OwnCloud I figured out that OwnCloud
has multiple not patched vulnerabilities.
You can see list here it seems all patches missing from latest Nextcloud 10.0.1
release in OwnCloud: https://nextcloud.com/security/advisories. This seems to
include XSS vulns and more.
An example exploit for one of the vulns would look like that:
http://demo.owncloud.org/index.php/apps/gallery/#<script>alert(document.domain)</script>/%00
And also RhinosSecurity seem to have blogged about unfixed vulns in OwnCloud:
https://rhinosecuritylabs.com/2016/10/operation-ownedcloud-exploitation-post-exploitation-persistence/;
Hope that OwnCloud fixes this soon!
Cheers
Matei Felix
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: http://seclists.org/fulldisclosure/