CVE-2012-5665
Description
ownCloud 4.0.x before 4.0.10 and 4.5.x before 4.5.5 fails to restrict access to settings.php, allowing remote attackers to modify app configurations.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
ownCloud 4.0.x before 4.0.10 and 4.5.x before 4.5.5 fails to restrict access to settings.php, allowing remote attackers to modify app configurations.
Vulnerability
ownCloud versions 4.0.x before 4.0.10 and 4.5.x before 4.5.5 do not properly restrict access to settings.php [2]. This file is used to store configuration for the user_webdavauth and user_ldap apps. Without proper access controls, any remote user can read and modify these settings [4].
Exploitation
An unauthenticated remote attacker can directly access settings.php via HTTP requests. By editing the file, the attacker can alter the configuration parameters for the user_webdavauth and user_ldap apps. No special privileges or user interaction is required [2][4].
Impact
Successful exploitation allows the attacker to modify app configurations, potentially leading to authentication bypass or unauthorized access to the ownCloud instance. The attacker can change LDAP or WebDAV authentication settings, which may compromise the integrity and confidentiality of user data [2].
Mitigation
The issue is fixed in ownCloud 4.0.10 and 4.5.5, released in December 2012 [1][3]. Users should upgrade to these versions or later. No workaround is documented. The fix adds an admin check before allowing access to settings.php [4].
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
16cpe:2.3:a:owncloud:owncloud_server:4.0.0:*:*:*:*:*:*:*+ 14 more
- cpe:2.3:a:owncloud:owncloud_server:4.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:4.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:4.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:4.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:4.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:4.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:4.0.6:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:4.0.7:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:4.0.8:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:4.0.9:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:4.5.0:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:4.5.1:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:4.5.2:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:4.5.3:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:4.5.4:*:*:*:*:*:*:*
Patches
2db7ca53c4ecbadVulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- github.com/owncloud/core/commit/db7ca53nvdPatch
- github.com/owncloud/core/commit/c4ecbadnvdExploitPatch
- secunia.com/advisories/51614nvdVendor Advisory
- owncloud.org/changelog/nvd
- www.openwall.com/lists/oss-security/2012/12/22/2nvd
- www.openwall.com/lists/oss-security/2012/12/22/5nvd
- www.securityfocus.com/bid/57030nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/80808nvd
News mentions
0No linked articles in our index yet.