Lucene search

K
owncloudOwnCloudOC-SA-2013-012
HistoryApr 02, 2013 - 11:42 a.m.

Server: contacts: SQL Injection

2013-04-0211:42:22
owncloud.org
18

EPSS

0.002

Percentile

56.1%

ownCloud before 5.0.1 does not neutralize special elements that are passed to the SQL query in addressbookprovider.php which therefore allows an authenticated attacker to execute arbitrary SQL commands.


For more information please consult the official advisory.

This advisory is licensed CC BY-SA 4.0

EPSS

0.002

Percentile

56.1%