PT-2012-5366 · Owncloud · Owncloud

Kurt Seifried

·

Publicado

2012-09-05

·

Atualizado

2025-03-31

·

CVE-2012-4392

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ownCloud version 4.0.7
Description The issue concerns improper validation of the oc token cookie in the index.php file, allowing remote attackers to bypass authentication by crafting a specific oc token cookie value.
Recommendations For ownCloud version 4.0.7, consider updating to a newer version that properly validates the oc token cookie to prevent authentication bypass. As a temporary workaround, restrict access to sensitive areas of the application to minimize the risk of exploitation.

Exploit

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-4392

Produtos afetados

Owncloud