Unrated severityNVD Advisory· Published Sep 5, 2012· Updated Apr 29, 2026
CVE-2012-4392
CVE-2012-4392
Description
index.php in ownCloud 4.0.7 does not properly validate the oc_token cookie, which allows remote attackers to bypass authentication via a crafted oc_token cookie value.
Affected products
1- cpe:2.3:a:owncloud:owncloud_server:4.0.7:*:*:*:*:*:*:*
Patches
14fd069b47906https://github.com/owncloud/corevia nvd-ref
Vulnerability mechanics
Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
3News mentions
0No linked articles in our index yet.