CVE Vulnerabilities

CVE-2012-5057

Published: Jun 04, 2014 | Modified: Mar 31, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

CRLF injection vulnerability in ownCloud Server before 4.0.8 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the url path parameter.

Affected Software

Name Vendor Start Version End Version
Owncloud Owncloud * 4.0.7 (including)
Owncloud_server Owncloud 4.0.0 (including) 4.0.0 (including)
Owncloud_server Owncloud 4.0.1 (including) 4.0.1 (including)
Owncloud_server Owncloud 4.0.2 (including) 4.0.2 (including)
Owncloud_server Owncloud 4.0.3 (including) 4.0.3 (including)
Owncloud_server Owncloud 4.0.4 (including) 4.0.4 (including)
Owncloud_server Owncloud 4.0.5 (including) 4.0.5 (including)
Owncloud_server Owncloud 4.0.6 (including) 4.0.6 (including)
Owncloud Ubuntu upstream *

References