Sploitus

CVE-2016-9467

No indexed exploits for CVE-2016-9467 yet

Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the files app. The location bar in the files app was not verifying the passed parameters. An attacker could craft an invalid link to a fake directory structure and use this to display an attacker-controlled error message to the user.

Nextcloud Nextcloud Server
< 9.0.54, 10.0.1
Owncloud
< 9.0.6, 9.1.2
Fix
Available
CVSS 3.0
5.3 MEDIUM
EPSS
3.0% (86th percentile)
Weakness
CWE-284, CWE-451
NVD status
Modified
Published
2017-03-28
CVE-2016-9467 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2016-9467 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2016-9467 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.