Skip to content

Latest commit

 

History

History
269 lines (265 loc) · 33 KB

TOPNEXTCLOUD.md

File metadata and controls

269 lines (265 loc) · 33 KB

Back

Top reports from Nextcloud program at HackerOne:

  1. Code injection possible with malformed Nextcloud Talk chat commands to Nextcloud - 189 upvotes, $3000
  2. User can delete data in shared folders he's not autorized to access to Nextcloud - 162 upvotes, $250
  3. Access to all files of remote user through shared file to Nextcloud - 145 upvotes, $750
  4. Missing ownership check on remote wipe endpoint to Nextcloud - 119 upvotes, $500
  5. Remote Code Execution via Extract App Plugin to Nextcloud - 119 upvotes, $0
  6. Arbitrary SQL command injection to Nextcloud - 69 upvotes, $500
  7. File-drop content is visible through the gallery app to Nextcloud - 65 upvotes, $500
  8. Extremly simple way to bypass Nextcloud-Client PIN/Fingerprint lock to Nextcloud - 54 upvotes, $100
  9. [Reflected XSS] In Request URL to Nextcloud - 37 upvotes, $50
  10. Remote code execution via path traversal in Zip extraction in the Extract app to Nextcloud - 37 upvotes, $0
  11. Expired reshare links allow access to all files in share to Nextcloud - 36 upvotes, $400
  12. No session logout after changing password & alsoandroid sessions not shown in sessions list so they can be deleted to Nextcloud - 35 upvotes, $50
  13. Passwords being stored as plain text in logging to Nextcloud - 30 upvotes, $0
  14. Group admins can remove arbitrary data from "data" directory (including admin data) to Nextcloud - 29 upvotes, $150
  15. Group admins can remove arbitrary data from "data" directory (including admin data) to Nextcloud - 29 upvotes, $150
  16. Code injection in macOS Desktop Client to Nextcloud - 27 upvotes, $250
  17. CSRF vulnerability that allows an attacker to modify encryption settings to Nextcloud - 27 upvotes, $0
  18. Reflected XSS in error pages (NC-SA-2017-008) to Nextcloud - 25 upvotes, $450
  19. SQL Injection found in NextCloud Android App Content Provider to Nextcloud - 25 upvotes, $150
  20. I am because bug to Nextcloud - 25 upvotes, $0
  21. http://www.nextcloud.com/wp-includes/js/swfupload/swfupload.swf allows open redirect / site defacement to Nextcloud - 25 upvotes, $0
  22. Persistent XSS via filename in projects to Nextcloud - 22 upvotes, $150
  23. Stored XSS on Share-popup of a directory's Gallery-view to Nextcloud - 21 upvotes, $750
  24. "Secure View" aka "Hide Download" can be bypassed easily to Nextcloud - 20 upvotes, $100
  25. Gallery: No feedback for invalid password to Nextcloud - 19 upvotes, $50
  26. Log pollution can lead to HTML Injection. to Nextcloud - 18 upvotes, $350
  27. Username and Access Token Disclousure to Nextcloud - 18 upvotes, $250
  28. SQLi allow query restriction bypass on exposed FileContentProvider to Nextcloud - 18 upvotes, $100
  29. Server side request forgery (SSRF) on nextcloud implementation. to Nextcloud - 18 upvotes, $0
  30. bypass of 2FA to Nextcloud - 17 upvotes, $750
  31. OAuth2 Access Token and App Password Security Vulnerability to Nextcloud - 17 upvotes, $400
  32. Session fixation in password protected public download. to Nextcloud - 17 upvotes, $50
  33. Reflected XSS / Markup Injection in index.php/svg/core/logo/logo parameter color to Nextcloud - 17 upvotes, $50
  34. https://help.nextcloud.com::: Web cache poisoning attack to Nextcloud - 17 upvotes, $0
  35. DOM XSS vulnerability in search dialogue (NC-SA-2017-007) to Nextcloud - 16 upvotes, $250
  36. User with read-only access to a share can gain write access to sub-folders in the share to Nextcloud - 16 upvotes, $250
  37. Access control issue -- [Allow file system access not validated when using session auth] to Nextcloud - 16 upvotes, $100
  38. XSS in PDF Viewer to Nextcloud - 16 upvotes, $100
  39. Response Header injection using redirect_uri together with PHP that utilizes Header Folding according to RFC1945 and Internet Explorer 11 to Nextcloud - 15 upvotes, $0
  40. IDOR unsubscribe Anyone from NextClouds Newsletters by knowing their Email to Nextcloud - 15 upvotes, $0
  41. Nextcloud domain and name of every user leaked to lookup server to Nextcloud - 14 upvotes, $100
  42. Docker image with FPM is vulnerable to CVE-2019-11043 to Nextcloud - 14 upvotes, $100
  43. Nextcloud 10.0 privilege escalation issue - Normal user can mask external storage shared by admin to Nextcloud - 14 upvotes, $50
  44. Unauthenticated Stored xss to Nextcloud - 14 upvotes, $0
  45. Content Spoofing /Text Injection in https://docs.nextcloud.com to Nextcloud - 14 upvotes, $0
  46. Only the file extensions are checked, not the MIME types as configured to Nextcloud - 13 upvotes, $175
  47. Registered users can change app password permissions for any user to Nextcloud - 13 upvotes, $100
  48. Delete permission can be added on reshare to Nextcloud - 13 upvotes, $100
  49. Blind Stored XSS on iOS App due to Unsanitized Webview to Nextcloud - 13 upvotes, $100
  50. SSRF protection bypass to Nextcloud - 13 upvotes, $100
  51. Authentication Issue to Nextcloud - 13 upvotes, $50
  52. Design Issues on ( ███ ) Lead to show ( IPS of Users ) to Nextcloud - 13 upvotes, $0
  53. Content Spoofing/Text Injection in https://demo.nextcloud.com to Nextcloud - 13 upvotes, $0
  54. Combination of content provider allows private data disclosure to Nextcloud - 12 upvotes, $100
  55. Remote attacker can impersonate Social users via ActivityPub API to Nextcloud - 12 upvotes, $50
  56. Talk / spreed: Disclosure of Room names and participants for password protected rooms to Nextcloud - 12 upvotes, $50
  57. WordPress <= 4.6.1 Stored XSS Via Theme File to Nextcloud - 12 upvotes, $0
  58. Disclosure of administrators via JSON on nextcloud.com Wordpress to Nextcloud - 12 upvotes, $0
  59. Wordpress 4.7.1 to Nextcloud - 12 upvotes, $0
  60. https://portal.nextcloud.com/.htaccess file is readable to Nextcloud - 12 upvotes, $0
  61. Predictable Random Number Generator to Nextcloud - 12 upvotes, $0
  62. Bypassing lock protection to Nextcloud - 11 upvotes, $50
  63. No Rate Limiting on stats.nextcloud.com login to Nextcloud - 11 upvotes, $0
  64. Content spoofing in lookup.nextcloud.com to Nextcloud - 11 upvotes, $0
  65. Android - Possible to intercept broadcasts about uploaded files to Nextcloud - 11 upvotes, $0
  66. Exposing debug.log file leads to server full path disclosure to Nextcloud - 11 upvotes, $0
  67. Able to bypass "Device credentials" Lock to Nextcloud - 10 upvotes, $100
  68. Group admin can remove user from all his groups via API to Nextcloud - 10 upvotes, $0
  69. Reflected XSS in U2F plugin by shipping the example endpoints to Nextcloud - 10 upvotes, $0
  70. Invalid request may lead content spoofing for phishing to Nextcloud - 10 upvotes, $0
  71. bug reporting template encourages users to paste config file with passwords to Nextcloud - 10 upvotes, $0
  72. https://xmpp.nextcloud.com///;@www.google.com allows open redirect to Nextcloud - 10 upvotes, $0
  73. Stored XSS in OAuth redirect URI to Nextcloud - 10 upvotes, $0
  74. In Dockerized Environments, Failing to Read config.php Grants Any Anonymous User Full Admin Access to Nextcloud - 10 upvotes, $0
  75. The password recovery let users know whether an email address exists or not in the website to Nextcloud - 10 upvotes, $0
  76. WordPress vulnerable to multiple attacks at https://nextcloud.com to Nextcloud - 10 upvotes, $0
  77. Self xss to Nextcloud - 10 upvotes, $0
  78. Bypass permissions to Nextcloud - 9 upvotes, $750
  79. Uploading files to a folder where invited user don't have any EDIT privilege to Nextcloud - 9 upvotes, $250
  80. [FG-VD-17-063] NextCloud Insufficient Attack Protection Vulnerability Notification to Nextcloud - 9 upvotes, $100
  81. Some HTML Tags are Getting Executed in com.nextcloud.client to Nextcloud - 9 upvotes, $50
  82. help.nextcloud Email Address/Username enumeration to Nextcloud - 9 upvotes, $0
  83. Bruteforcing help.nextcloud.com to Nextcloud - 9 upvotes, $0
  84. \OCA\DAV\CardDAV\ImageExportPlugin allows serving arbitrary data with user-defined or empty mimetype to Nextcloud - 9 upvotes, $0
  85. Privilege escalation - Normal user can somehow make admin to delete shared folders to Nextcloud - 9 upvotes, $0
  86. The session token in the URL to Nextcloud - 9 upvotes, $0
  87. User Editable nextcloud Wiki pages of Public Repositories to Nextcloud - 9 upvotes, $0
  88. Delete All Data of Any User to Nextcloud - 8 upvotes, $250
  89. Share recipient can modify a share's expiration date to Nextcloud - 8 upvotes, $100
  90. twofactor_auth bypassable if provider fails to load to Nextcloud - 8 upvotes, $50
  91. Uploading large avatar images cause excessive CPU usage to Nextcloud - 8 upvotes, $50
  92. Files Drop: WebDAV endpoint is leaking existence of resources to Nextcloud - 8 upvotes, $0
  93. User Information Disclosure via REST API to Nextcloud - 8 upvotes, $0
  94. Wordpress Vulnerable to Potential Unauthorized Password Reset to Nextcloud - 8 upvotes, $0
  95. Update App Store: Django account high jacking vulnerability to Nextcloud - 8 upvotes, $0
  96. Directory listing is enabled that exposes non public data through multiple path to Nextcloud - 8 upvotes, $0
  97. Password of failed (2FA) login attempt is stored in log to Nextcloud - 8 upvotes, $0
  98. Allows any user to share their "Root" level folder by sharing "." to Nextcloud - 8 upvotes, $0
  99. Reflected XSS in Gallery App to Nextcloud - 7 upvotes, $500
  100. Calendar and addressbook names disclosed (NC-SA-2017-012) to Nextcloud - 7 upvotes, $183
  101. Server-Side request forgery in New-Subscription feature of the calendar app to Nextcloud - 7 upvotes, $100
  102. Content (Text) Injection at NextCloud Server 9.0.52 - via http://custom_nextcloud_url/remote.php/dav/files/ to Nextcloud - 7 upvotes, $50
  103. Bad content-type in response header when getting document can lead to html injection to Nextcloud - 7 upvotes, $0
  104. Update php-saml library to 2.10.5 to Nextcloud - 7 upvotes, $0
  105. Missing Rate Limit for Current Password field in nextcloud.com to Nextcloud - 7 upvotes, $0
  106. WordPress < 4.8.2 vulnerable to multiple attacks to Nextcloud - 7 upvotes, $0
  107. Github wikis are editable by anyone to Nextcloud - 7 upvotes, $0
  108. Wordpress Users Disclosure to Nextcloud - 7 upvotes, $0
  109. Click Jacking Nextcloud to Nextcloud - 7 upvotes, $0
  110. (Authenticated) RCE by bypassing of the .htaccess blacklist to Nextcloud - 7 upvotes, $0
  111. Disabled user can reset their password to Nextcloud - 7 upvotes, $0
  112. File access control rules not enforced on image files to Nextcloud - 6 upvotes, $150
  113. Stored XSS/HTML injection in autocomplete suggestions for sharing to Nextcloud - 6 upvotes, $100
  114. Event privacy level does not work in Thunderbird to Nextcloud - 6 upvotes, $100
  115. Android content provider exposes password-protected share password hashes to Nextcloud - 6 upvotes, $75
  116. Improper protection of FileContentProvider to Nextcloud - 6 upvotes, $50
  117. Expired SSL certificate to Nextcloud - 6 upvotes, $0
  118. Wordpress: Directory Traversal / Denial of Serivce to Nextcloud - 6 upvotes, $0
  119. Directory listening enabled in: 88.198.160.130 to Nextcloud - 6 upvotes, $0
  120. XSS on IOS app via HTML rendering to Nextcloud - 6 upvotes, $0
  121. Content spoofing due to the improper behavior of the 403 page to Nextcloud - 6 upvotes, $0
  122. Email Notification should be get while changing password on apps.nextcloud.com to Nextcloud - 6 upvotes, $0
  123. NextCloud is also Accepting OCTET-STREAM Type of Documents instead of jpg or Imge Files Only to Nextcloud - 6 upvotes, $0
  124. Private/confidential setting of calendar events is ignored on activity stream to Nextcloud - 6 upvotes, $0
  125. SQL exception in JSON format to Nextcloud - 6 upvotes, $0
  126. xmlrpc.php is enabled - Nextcloud to Nextcloud - 6 upvotes, $0
  127. Share owner has no possibility to list all existing derived shares to Nextcloud - 5 upvotes, $350
  128. Read-only share recipient can restore old versions of file to Nextcloud - 5 upvotes, $300
  129. Limitation of app specific password scope can be bypassed (NC-SA-2017-009) to Nextcloud - 5 upvotes, $300
  130. Talk - Leak of password-protected room name via already existent resource addition to Nextcloud - 5 upvotes, $150
  131. IDOR - Disable sharing to Nextcloud - 5 upvotes, $100
  132. More content spoofing through dir param in the files app to Nextcloud - 5 upvotes, $50
  133. Shared file link - password protection bypass under certain conditions to Nextcloud - 5 upvotes, $50
  134. nextcloud.com: Content Injection Custom 404 Error to Nextcloud - 5 upvotes, $0
  135. Password Reset Link issue to Nextcloud - 5 upvotes, $0
  136. Wordpress Version Disclosure Bug On Nextcloud to Nextcloud - 5 upvotes, $0
  137. URI scheme bypass in mail app lead to HTML content spoof and opener control to Nextcloud - 5 upvotes, $0
  138. Missing SPF Flags on nextcloud.com to Nextcloud - 5 upvotes, $0
  139. Drone Nextcloud to Nextcloud - 5 upvotes, $0
  140. Version 4.7.2 of wordpress is vulnerable to Nextcloud - 5 upvotes, $0
  141. Content Spoofing/Text Injection in nextcloud.com to Nextcloud - 5 upvotes, $0
  142. GIT Detected to Nextcloud - 5 upvotes, $0
  143. Content spoofing due to the improper behavior of the 403 page to Nextcloud - 5 upvotes, $0
  144. Dav sharing permissions issue to Nextcloud - 5 upvotes, $0
  145. Possible RCE to Nextcloud - 5 upvotes, $0
  146. Banner Grabbing - Apache Server Version Disclousure to Nextcloud - 5 upvotes, $0
  147. HTML injection with AutoComplete suggestions to Nextcloud - 5 upvotes, $0
  148. Vulnerable W3 Total Cache plugin version in use on nextcloud.com to Nextcloud - 5 upvotes, $0
  149. Passcode Protection in Android Devices Can be Bypassed. to Nextcloud - 5 upvotes, $0
  150. Missing DNSSEC to Nextcloud - 5 upvotes, $0
  151. HTML injection and limited XSS via logo image upload - Nextcloud 12.0.0 to Nextcloud - 5 upvotes, $0
  152. Email Spoofing to Nextcloud - 5 upvotes, $0
  153. SSRF on local storage of iOS mobile to Nextcloud - 5 upvotes, $0
  154. DOMPurify 0.8.9 released to Nextcloud - 5 upvotes, $0
  155. Mail does not verify IMAP/SMTP host connected via TLS to Nextcloud - 5 upvotes, $0
  156. Filename enumeration && DoS to Nextcloud - 4 upvotes, $250
  157. Content Spoofing in "files" app to Nextcloud - 4 upvotes, $50
  158. nextcloud.com: Directory listening for 'wp-includes' forders to Nextcloud - 4 upvotes, $0
  159. Enumeration of subscribed users and unauthenticated email unsubscriptions on https://newsletter.nextcloud.com/?p=unsubscribe to Nextcloud - 4 upvotes, $0
  160. Email ID Disclosure. to Nextcloud - 4 upvotes, $0
  161. REG: Content provider information leakage to Nextcloud - 4 upvotes, $0
  162. stats.nextcloud.com: Content Injection to Nextcloud - 4 upvotes, $0
  163. help.nextcloud.com: Known DoS condition (null pointer deref) in Nginx running to Nextcloud - 4 upvotes, $0
  164. Bookmarks: Delete all existing bookmarks of a user to Nextcloud - 4 upvotes, $0
  165. Information Disclosure of .htaccess file in Private Server/Subdomain to Nextcloud - 4 upvotes, $0
  166. Content spoofing due to the improper behavior of the 403 page in Private Server to Nextcloud - 4 upvotes, $0
  167. [Thirdparty] Stored XSS in chat module - nextcloud server 9.0.51 installed in ubuntu 14.0.4 LTS to Nextcloud - 4 upvotes, $0
  168. Stored XSS on new Calling plugin (spreed) to Nextcloud - 4 upvotes, $0
  169. HTTP-Basic Authentication on logs.nextcloud.com to Nextcloud - 4 upvotes, $0
  170. Email Spoofing to Nextcloud - 4 upvotes, $0
  171. Review remote code execution in SwiftMailer to Nextcloud - 4 upvotes, $0
  172. Bypassing quota limit to Nextcloud - 4 upvotes, $0
  173. Clickjacking In https://demo.nextcloud.com to Nextcloud - 4 upvotes, $0
  174. Missing Rate Limiting protection leading to mass triggering of e-mails to Nextcloud - 4 upvotes, $0
  175. Information Exposure Through Directory Listing to Nextcloud - 4 upvotes, $0
  176. Missing SPF flags for customerupdates.nextcloud.com to Nextcloud - 4 upvotes, $0
  177. Stored XSS on scan.nextcloud.com to Nextcloud - 4 upvotes, $0
  178. Unauthenticated 'display name' information leak on enumeration of login names to Nextcloud - 4 upvotes, $0
  179. potential RCE and XSS via file upload requiring user account and default settings to Nextcloud - 4 upvotes, $0
  180. Reflected Self-XSS Vulnerability in the Comment section of Files Information to Nextcloud - 3 upvotes, $100
  181. Vulnerable Javascript library to Nextcloud - 3 upvotes, $0
  182. No captcha on newsletter.nextcloudcom leaves vulnerable to email spammers to Nextcloud - 3 upvotes, $0
  183. Content Spoofing/Text Injection - docs.nextcloud.org to Nextcloud - 3 upvotes, $0
  184. Business/Functional logic bypass: Remove admins from admin group. to Nextcloud - 3 upvotes, $0
  185. Content injection in subdomain to Nextcloud - 3 upvotes, $0
  186. WordPress Vulnerabilities: User Enumeration, Vulnerable Akismet Plugin, XML-RPC Interface available to Nextcloud - 3 upvotes, $0
  187. newsletter.nextcloud.com: Bypass firewall protection to Nextcloud - 3 upvotes, $0
  188. Avatar image upload and bypass real image verification to Nextcloud - 3 upvotes, $0
  189. xss for admin of https://newsletter.nextcloud.com to Nextcloud - 3 upvotes, $0
  190. SSRF at apps.nextcloud.com/developer/apps/releases/new to Nextcloud - 3 upvotes, $0
  191. Nextcloud Server Remote Command Execution to Nextcloud - 3 upvotes, $0
  192. Banner Grabbing - Apache Server Version Disclosure to Nextcloud - 3 upvotes, $0
  193. Retrieval and alteration of exposed media on Android Oreo to Nextcloud - 3 upvotes, $0
  194. LDAP login possible even though account doesn't match user filter to Nextcloud - 3 upvotes, $0
  195. W3 Total Cache plugin multiple vulnerabilities to Nextcloud - 3 upvotes, $0
  196. SignUp using Fake Email to Nextcloud - 3 upvotes, $0
  197. Veracode and security audit record are publicly available to Nextcloud - 3 upvotes, $0
  198. Persistent XSS on favorite via filename to Nextcloud - 3 upvotes, $0
  199. Missing X-Content-Type-Options to Nextcloud - 3 upvotes, $0
  200. **minor issue ** -Nextcloud 10.0 session issue with desktop client and android client to Nextcloud - 3 upvotes, $0
  201. Circle email-members have still access to a shared folder/file after they are removed from the circle to Nextcloud - 2 upvotes, $200
  202. Nextcloud server software: Content Spoofing to Nextcloud - 2 upvotes, $50
  203. help.nextcloud.com: Session Management Issue to Nextcloud - 2 upvotes, $0
  204. Directory Listing On download.nextcloud.com & Practical Attacks on PGP (Pretty Good Privacy) to Nextcloud - 2 upvotes, $0
  205. https://newsletter.nextcloud.com Directory listening and Information Disclosure to Nextcloud - 2 upvotes, $0
  206. Lost Password CSRF to Nextcloud - 2 upvotes, $0
  207. Content Spoofing to Nextcloud - 2 upvotes, $0
  208. Content Injection 404 page to Nextcloud - 2 upvotes, $0
  209. Content Injection in subdomain to Nextcloud - 2 upvotes, $0
  210. No rate limiting on password protected shared file link to Nextcloud - 2 upvotes, $0
  211. Deny access to download.nextcloud.com + folders to Nextcloud - 2 upvotes, $0
  212. nextcloud.com: Mail Bombing ( No Rate Limiting On Sending Emails On Contact us Page) to Nextcloud - 2 upvotes, $0
  213. Content Injection - apps.nextcloud.com to Nextcloud - 2 upvotes, $0
  214. Content spoofing in cloud.nextcloud.com to Nextcloud - 2 upvotes, $0
  215. Reflected Self-XSS Vulnerability in the Comment section of Files (Different-payloads) to Nextcloud - 2 upvotes, $0
  216. demo.nextcloud.com: Content spoofing due to default Apache Error Page to Nextcloud - 2 upvotes, $0
  217. Arbitrary File Upload in Logo & Log in image Theming setting. to Nextcloud - 2 upvotes, $0
  218. Password reset link remains valid after email change to Nextcloud - 2 upvotes, $0
  219. Nextcloud.com is vulnerable to SWEET32 attack to Nextcloud - 2 upvotes, $0
  220. Server version/OS type disclosure via HTTP Response Header to Nextcloud - 2 upvotes, $0
  221. CSRF token validation is missing to Nextcloud - 2 upvotes, $0
  222. Information disclosure to Nextcloud - 2 upvotes, $0
  223. information disclose to Nextcloud - 2 upvotes, $0
  224. Content (Text) Injection at https://nextcloud.com to Nextcloud - 2 upvotes, $0
  225. Email Spoofing Vulnerability from nextcloud. to Nextcloud - 2 upvotes, $0
  226. Share tokens for public calendars disclosed (NC-SA-2017-011) to Nextcloud - 2 upvotes, $0
  227. Stored XSS in Gallery application (NC-SA-2017-010) to Nextcloud - 2 upvotes, $0
  228. ci.nextcloud.com: CVE-2015-5477 BIND9 TKEY Vulnerability + Exploit (Denial of Service) to Nextcloud - 2 upvotes, $0
  229. Disclosed Version of PORTS SSH|HTTP|SSL to Nextcloud - 2 upvotes, $0
  230. Accessing to download.nextcloud.com from original ip adreess | insecure Download to Nextcloud - 2 upvotes, $0
  231. XSS On Nextcloud Integrated with zimbra drive to Nextcloud - 2 upvotes, $0
  232. Github repo's wiki publicly editable to Nextcloud - 2 upvotes, $0
  233. Nextcloud logs ldap passwords to Nextcloud - 2 upvotes, $0
  234. Bruteforce attack is possible on newsletter.nextcloud.com to Nextcloud - 1 upvotes, $0
  235. No permission set on Activities [Android App] to Nextcloud - 1 upvotes, $0
  236. The application uses basic authentication. to Nextcloud - 1 upvotes, $0
  237. Content Injection - demo.nextcloud.com to Nextcloud - 1 upvotes, $0
  238. demo.nextcloud.com: Content spoofing due to default Apache Error Page to Nextcloud - 1 upvotes, $0
  239. Slow Http attack on nextcloud(DOS) to Nextcloud - 1 upvotes, $0
  240. xss on demo.nextcloud.com due to outdated version to Nextcloud - 1 upvotes, $0
  241. BruteForce in to Admin Account to Nextcloud - 1 upvotes, $0
  242. Login Hints on Admin Panel to Nextcloud - 1 upvotes, $0
  243. [Nextcloud 9.0.53] Content Spoofing in 'trustDomain' parameter to Nextcloud - 1 upvotes, $0
  244. failure to invalidate session on password change to Nextcloud - 1 upvotes, $0
  245. The email API to reset password is unlimited and can be used as a email bomb to Nextcloud - 1 upvotes, $0
  246. The email API to test email-server settings is unlimited and can be used as a email bomb to Nextcloud - 1 upvotes, $0
  247. Cross Site Scripting to Nextcloud - 1 upvotes, $0
  248. Possible SSRF in email server settings(SMTP mode) to Nextcloud - 1 upvotes, $0
  249. Directory Listing In Subdomain Of nextcloud.com to Nextcloud - 1 upvotes, $0
  250. Clickjacking on https://download.nextcloud.com/ to Nextcloud - 1 upvotes, $0
  251. Nextcloud Clickjacking Vulnerability to Nextcloud - 1 upvotes, $0
  252. Bruteforce in admin panel to Nextcloud - 1 upvotes, $0
  253. Password authentication at newsletter.nextcloud.com discloses username list to Nextcloud - 1 upvotes, $0
  254. Bypass configured 2FA provider with another provider that can be set up at login to Nextcloud - 1 upvotes, $0
  255. WebDAV Empty Property search leads to full CPU usage to Nextcloud - 1 upvotes, $0
  256. Ubuntu 12.04 Privilege Escalation to Nextcloud - 0 upvotes, $0
  257. Information Exposure Through Directory Listing - https://apps.nextcloud.com/static/ to Nextcloud - 0 upvotes, $0
  258. WordPress Plugin Insert or Embed Articulate Content into WordPress Remote Code Execution (UNAUTHORIZED) to Nextcloud - 0 upvotes, $0
  259. Clickjacking on https://nextcloud.com/ to Nextcloud - 0 upvotes, $0
  260. Clickjacking on https://download.nextcloud.com to Nextcloud - 0 upvotes, $0
  261. Username Enumeration to Nextcloud - 0 upvotes, $0
  262. Broken link for wrong domain entry may be leveraged for Phishing, Misinformation, Serving Malware to Nextcloud - 0 upvotes, $0

Back