CVE-2016-9461
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are not properly verifying edit check permissions on WebDAV copy actions. The WebDAV endpoint was not properly checking the permission on a WebDAV COPY action. This allowed an authenticated attacker with access to a read-only share to put new files in there. It was not possible to modify existing files.
Nextcloud Server en versiones anteriores a 9.0.52 & ownCloud Server en versiones anteriores a 9.0.4 no están verificando correctamente los permisos de comprobación de edición en las acciones de copia de WebDAV. El punto final WebDAV no comprueba correctamente el permiso en una acción WebDAV COPY. Esto permitió a un atacante autenticado con acceso a un recurso compartido de solo lectura para poner allí nuevos archivos. No fue posible modificar los archivos existentes.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-11-19 CVE Reserved
- 2017-03-28 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-275: Permission Issues
- CWE-284: Improper Access Control
CAPEC
References (9)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/97276 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://hackerone.com/reports/145950 | 2024-08-06 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Nextcloud Search vendor "Nextcloud" | Nextcloud Server Search vendor "Nextcloud" for product "Nextcloud Server" | < 9.0.52 Search vendor "Nextcloud" for product "Nextcloud Server" and version " < 9.0.52" | - |
Affected
| ||||||
Owncloud Search vendor "Owncloud" | Owncloud Search vendor "Owncloud" for product "Owncloud" | < 9.0.4 Search vendor "Owncloud" for product "Owncloud" and version " < 9.0.4" | - |
Affected
|