CVE-2012-4392

Owncloud Server - Authentication Bypass

Title source: rule

Description

index.php in ownCloud 4.0.7 does not properly validate the oc_token cookie, which allows remote attackers to bypass authentication via a crafted oc_token cookie value.

Scores

EPSS 0.0034
EPSS Percentile 56.4%

Classification

CWE
CWE-287
Status draft

Affected Products (1)

owncloud/owncloud_server

Timeline

Published Sep 05, 2012
Tracked Since Feb 18, 2026