CVE-2012-5665 Information
Feb 14, 2021
cve
Description
ownCloud 4.0.x before 4.0.10 and 4.5.x before 4.5.5 does not properly restrict access to settings.php which allows remote attackers to edit app configurations of user_webdavauth and user_ldap by editing this file.
Reference
http://owncloud.org/changelog/ http://secunia.com/advisories/51614 http://www.openwall.com/lists/oss-security/2012/12/22/2 http://www.openwall.com/lists/oss-security/2012/12/22/5 http://www.securityfocus.com/bid/57030 https://exchange.xforce.ibmcloud.com/vulnerabilities/80808 https://github.com/owncloud/core/commit/c4ecbad https://github.com/owncloud/core/commit/db7ca53
Share on: