Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.106705
Category:Web application abuses
Title:Nextcloud Multiple Vulnerabilities - Windows
Summary:Nextcloud is prone to multiple vulnerabilities.
Description:Summary:
Nextcloud is prone to multiple vulnerabilities.

Vulnerability Insight:
Nextcloud is prone to multiple vulnerabilities:

- Stored XSS in CardDAV image export. (CVE-2016-9465)

- Reflected XSS in the Gallery application (CVE-2016-9466)

Affected Software/OS:
Nextcloud Server prior to 10.0.1

Solution:
Update 10.0.1 or later versions.

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2016-9465
https://github.com/nextcloud/server/commit/68ab8325c799d20c1fb7e98d670785176590e7d0
https://github.com/owncloud/core/commit/6bf3be3877d9d9fda9c66926fe273fe79cbaf58e
https://github.com/owncloud/core/commit/b5a5be24c418033cb2ef965a4f3f06b7b4213845
https://hackerone.com/reports/163338
https://nextcloud.com/security/advisory/?id=nc-sa-2016-008
https://owncloud.org/security/advisory/?id=oc-sa-2016-018
Common Vulnerability Exposure (CVE) ID: CVE-2016-9466
https://github.com/nextcloud/gallery/commit/f9ef505c1d60c9041e251682e0f6b3daad952d58
https://github.com/owncloud/gallery/commit/b3b3772fb9bec61ba10d357bef42b676fa474eee
https://github.com/owncloud/gallery/commit/dc4887f1afcc0cf304f4a0694075c9364298ad8a
https://hackerone.com/reports/165686
https://nextcloud.com/security/advisory/?id=nc-sa-2016-009
https://owncloud.org/security/advisory/?id=oc-sa-2016-019
CopyrightCopyright (C) 2017 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.