The default Flash Cross Domain policies in ownCloud before 5.0.15 and 6.x before 6.0.2 allows remote attackers to access user files via unspecified vectors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Owncloud | Owncloud | 6.0.0 (including) | 6.0.0 (including) |
Owncloud | Owncloud | 6.0.1 (including) | 6.0.1 (including) |
Owncloud | Ubuntu | quantal | * |
Owncloud | Ubuntu | saucy | * |
Owncloud | Ubuntu | upstream | * |