CVE-2016-9460
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are vulnerable to a content-spoofing attack in the files app. The location bar in the files app was not verifying the passed parameters. An attacker could craft an invalid link to a fake directory structure and use this to display an attacker-controlled error message to the user.
Nextcloud Server en versiones anteriores a 9.0.52 & ownCloud Server en versiones anteriores a 9.0.4 son vulnerables a un ataque de contenido falsificado en la aplicación de archivos. La barra de ubicación en la aplicación de archivos no estaba verificando los parámetros pasados. Un atacante podría manipular un enlace no válido a una estructura de directorio falsa y usar esto para mostrar un mensaje de error controlado por el atacante al usuario.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-11-19 CVE Reserved
- 2017-03-28 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-284: Improper Access Control
- CWE-451: User Interface (UI) Misrepresentation of Critical Information
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/97282 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://hackerone.com/reports/145463 | 2024-08-06 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Nextcloud Search vendor "Nextcloud" | Nextcloud Search vendor "Nextcloud" for product "Nextcloud" | <= 9.0.51 Search vendor "Nextcloud" for product "Nextcloud" and version " <= 9.0.51" | - |
Affected
| ||||||
Owncloud Search vendor "Owncloud" | Owncloud Search vendor "Owncloud" for product "Owncloud" | <= 9.0.3 Search vendor "Owncloud" for product "Owncloud" and version " <= 9.0.3" | - |
Affected
|