Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.809414
Category:Web application abuses
Title:Nextcloud 'share.js' Gallery Application XSS Vulnerability - Windows
Summary:Nextcloud is prone to a cross-site scripting (XSS) vulnerability.
Description:Summary:
Nextcloud is prone to a cross-site scripting (XSS) vulnerability.

Vulnerability Insight:
The flaw exists due to a recent migration
of the gallery app to the new sharing endpoint and a parameter changed from an
integer to a string value which is not sanitized properly.

Vulnerability Impact:
Successful exploitation will allow remote
authenticated users to inject arbitrary web script or HTML.

Affected Software/OS:
Nextcloud Server before 9.0.52 on Windows.

Solution:
Upgrade to Nextcloud Server 9.0.52 or later.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2016-7419
BugTraq ID: 92373
http://www.securityfocus.com/bid/92373
https://hackerone.com/reports/145355
Common Vulnerability Exposure (CVE) ID: CVE-2016-9459
BugTraq ID: 97284
http://www.securityfocus.com/bid/97284
https://github.com/nextcloud/server/commit/94975af6db1551c2d23136c2ea22866a5b416070
https://github.com/owncloud/core/commit/044ee072a647636b1a17c89265c7233b35371335
https://github.com/owncloud/core/commit/b7fa2c5dc945b40bc6ed0a9a0e47c282ebf043e1
https://github.com/owncloud/core/commit/efa35d621dc7ff975468e636a5d1c153511296dc
https://hackerone.com/reports/146278
https://nextcloud.com/security/advisory/?id=nc-sa-2016-002
https://owncloud.org/security/advisory?id=oc-sa-2016-012
Common Vulnerability Exposure (CVE) ID: CVE-2016-9460
BugTraq ID: 97282
http://www.securityfocus.com/bid/97282
https://github.com/nextcloud/server/commit/2da43e3751576bbc838f238a09955c4dcdebee8e
https://github.com/nextcloud/server/commit/8aa0832bd449c44ec300da4189bd8ed4e036140c
https://github.com/nextcloud/server/commit/dea8e29289a1b99d5e889627c2e377887f4f2983
https://github.com/owncloud/core/commit/c92c234059f8b1dc7d53122985ec0d398895a2cf
https://hackerone.com/reports/145463
https://nextcloud.com/security/advisory/?id=nc-sa-2016-003
https://owncloud.org/security/advisory/?id=oc-sa-2016-013
Common Vulnerability Exposure (CVE) ID: CVE-2016-9461
BugTraq ID: 97276
http://www.securityfocus.com/bid/97276
https://github.com/nextcloud/server/commit/3491400261c1454a9a30d3ec96969573330120cc
https://github.com/owncloud/core/commit/0622e635d97cb17c5e1363e370bb8268cc3d2547
https://github.com/owncloud/core/commit/121a3304a0c37ccda0e1b63ddc528cba9121a36e
https://github.com/owncloud/core/commit/acbbadb71ceee7f01da347f7dcd519beda78cc47
https://github.com/owncloud/core/commit/c0a4b7b3f38ad2eaf506484b3b92ec678cb021c9
https://hackerone.com/reports/145950
https://nextcloud.com/security/advisory/?id=nc-sa-2016-004
https://owncloud.org/security/advisory/?id=oc-sa-2016-014
Common Vulnerability Exposure (CVE) ID: CVE-2016-9462
BugTraq ID: 97285
http://www.securityfocus.com/bid/97285
https://github.com/nextcloud/server/commit/1208953ba1d4d55a18a639846bbcdd66a2d5bc5e
https://github.com/owncloud/core/commit/23383080731d092e079986464a8c4c9ffcb79f4c
https://github.com/owncloud/core/commit/3b056fa68ce502ceb0db9b446dab3b9e7b10dd13
https://github.com/owncloud/core/commit/c93eca49c32428ece03dd67042772d5fa62c8d6e
https://github.com/owncloud/core/commit/d31720b6f1e8c8dfeb5e8805ab35ad7c8000b2f1
https://hackerone.com/reports/146067
https://nextcloud.com/security/advisory/?id=nc-sa-2016-005
https://owncloud.org/security/advisory/?id=oc-sa-2016-015
CopyrightCopyright (C) 2016 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.