CVE-2012-2269
ownCloud 3.0.0 Cross Site Scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 3.0.3 allow remote attackers to inject arbitrary web script or HTML via (1) an arbitrary field to apps/contacts/ajax/addcard.php, (2) the parameter parameter to apps/contacts/ajax/addproperty.php, (3) the name parameter to apps/contacts/ajax/createaddressbook, (4) the file parameter to files/download.php, or the (5) name, (6) user, or (7) redirect_url parameter to files/index.php.
Múltiples vulnerabilidades de ejecución de comandos en sitios cruzados (XSS) en ownCloud v3.0.0 permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de (1) un campo arbitrario a apps/contacts/AJAX/addcard.php, (2) el parámetro 'parameter' a apps/contacts/AJAX/addproperty.php, (3) el parámetro 'name a apps/contacts/AJAX/createaddressbook, (4) el parámetro 'file' a files/download.php, o los parámetros (5) 'name', (6) 'user', o (7) 'redirect_url' a files/index.php.
ownCloud version 3.0.0 suffers from cross site scripting and open redirection vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-04-17 CVE Reserved
- 2012-04-18 CVE Published
- 2024-05-09 EPSS Updated
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (13)
URL | Tag | Source |
---|---|---|
http://archives.neohapsis.com/archives/bugtraq/2012-04/0127.html | Mailing List | |
http://osvdb.org/81206 | Vdb Entry | |
http://osvdb.org/81207 | Vdb Entry | |
http://osvdb.org/81208 | Vdb Entry | |
http://osvdb.org/81209 | Vdb Entry | |
http://osvdb.org/81210 | Vdb Entry | |
http://owncloud.org/security/advisories/CVE-2012-2269 | X_refsource_confirm | |
http://www.openwall.com/lists/oss-security/2012/08/11/1 | Mailing List | |
http://www.openwall.com/lists/oss-security/2012/09/02/2 | Mailing List | |
http://www.securityfocus.com/bid/53145 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/75028 | Vdb Entry |
URL | Date | SRC |
---|---|---|
http://www.tele-consulting.com/advisories/TC-SA-2012-01.txt | 2024-08-06 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/48850 | 2018-01-04 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Owncloud Search vendor "Owncloud" | Owncloud Search vendor "Owncloud" for product "Owncloud" | <= 3.0.2 Search vendor "Owncloud" for product "Owncloud" and version " <= 3.0.2" | - |
Affected
| ||||||
Owncloud Search vendor "Owncloud" | Owncloud Search vendor "Owncloud" for product "Owncloud" | 3.0.0 Search vendor "Owncloud" for product "Owncloud" and version "3.0.0" | - |
Affected
| ||||||
Owncloud Search vendor "Owncloud" | Owncloud Search vendor "Owncloud" for product "Owncloud" | 3.0.1 Search vendor "Owncloud" for product "Owncloud" and version "3.0.1" | - |
Affected
|