Nextcloud

Note!!! Приглядитесь к репортам на h1, некоторым вулнам не назначали cve

1.Recon

find version

https://target/status.php

find api

https://target/ocs-provider/

Nextcloud Detection

nuclei -u target -t nextcloud-detect.yaml

2.Exploit

brureforce api

https://target/public.php/webdav
https://target/remote.php/dav/files/USERNAME/

Nextcloud Exposed Installation

nuclei -u target -t nextcloud-install.yaml

3. Recommend

disable the web-based upgrader simply set 'upgrade.disable-web' => true, in nextcloud’s config.php with this result:

4. Reports

Nextcloud program at HackerOne

  1. Arbitrary SQL command injectionarrow-up-right to Nextcloud - 73 upvotes, $500

  2. [Reflected XSS] In Request URLarrow-up-right to Nextcloud - 37 upvotes, $50

  3. I am because bugarrow-up-right to Nextcloud - 29 upvotes, $0

refrencess

Last updated