CVE-2013-2047
Published: 14 March 2014
The login page (aka index.php) in ownCloud before 5.0.6 does not disable the autocomplete setting for the password parameter, which makes it easier for physically proximate attackers to guess the password.
Notes
Author | Note |
---|---|
jdstrand | per upstream, 5.0 only |
Priority
Status
Package | Release | Status |
---|---|---|
owncloud Launchpad, Ubuntu, Debian |
lucid |
Does not exist
|
precise |
Not vulnerable
|
|
quantal |
Not vulnerable
(4.0.8debian-1.1ubuntu0.1)
|
|
raring |
Ignored
(end of life)
|
|
saucy |
Not vulnerable
(5.0.10+dfsg-1ubuntu1)
|
|
trusty |
Does not exist
(trusty was not-affected [6.0.1+dfsg-1ubuntu1])
|
|
upstream |
Released
(5.0.6)
|