← Back

CVE-2016-1499

nvd nist
Published: Jan 8, 2016Modified: May 6, 2026

JSON object

Loading...
8.5
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:H
Exploitability: 3.1 / Impact: 4.7
Source: NVD

Description

ownCloud Server before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2 allow remote authenticated users to obtain sensitive information from a directory listing and possibly cause a denial of service (CPU consumption) via the force parameter to index.php/apps/files/ajax/scan.php.

Affected (7)

2 products
Owncloud
Owncloud Server
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Owncloud
Up to 8.0.9
Version 8.2.0
Version 8.2.1
Owncloud
Version 8.1.0
Version 8.1.1
Version 8.1.3
Version 8.1.4

Timeline

No history available yet.