CVE Vulnerabilities

CVE-2013-2047

Published: Mar 14, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The login page (aka index.php) in ownCloud before 5.0.6 does not disable the autocomplete setting for the password parameter, which makes it easier for physically proximate attackers to guess the password.

Affected Software

NameVendorStart VersionEnd Version
OwncloudOwncloud*5.0.5 (including)
Owncloud_serverOwncloud5.0.0 (including)5.0.0 (including)
Owncloud_serverOwncloud5.0.1 (including)5.0.1 (including)
Owncloud_serverOwncloud5.0.2 (including)5.0.2 (including)
Owncloud_serverOwncloud5.0.3 (including)5.0.3 (including)
Owncloud_serverOwncloud5.0.4 (including)5.0.4 (including)
OwncloudUbunturaring*
OwncloudUbuntuupstream*

References