ownCloud是美国ownCloud公司的一套个人云存储解决方案。 OwnCloud 4.0.10及之前版本和4.5.5及之前版本中存在跨站脚本漏洞,该漏洞源于通过POST参数传递给apps/calendar/ajax/event/new.php,url参数传递给apps/bookmarks/ajax/addBookmark.php的输入在返回用户之前缺少过滤。攻击者可利用这些漏洞注入任意HTML和脚本代码,可获得敏感信息或者劫持用户会话。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ownCloud | ownCloud Server | 4.5.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet