CVE-2012-2398: XSS
Published Apr 20, 2012
·Updated
Cross-site scripting (XSS) vulnerability in files/ajax/download.php in ownCloud before 3.0.3 allows remote attackers to inject arbitrary web script or HTML via the files parameter, a different vulnerability than CVE-2012-2269.4.
Affected Software
5 affected components
ownCloud ownCloud<=3.0.2
ownCloud ownCloud=3.0.0
ownCloud ownCloud=3.0.1
ownCloud ownCloud Server=3.0.0
ownCloud ownCloud Server=3.0.1
Event History
Apr 20, 2012
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Data Sourced
via NVD·10:55 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2012-2398?
CVE-2012-2398 has a medium severity rating due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2012-2398?
To fix CVE-2012-2398, upgrade ownCloud to version 3.0.3 or later.
3
What systems are affected by CVE-2012-2398?
CVE-2012-2398 affects ownCloud versions prior to 3.0.3, including 3.0.0, 3.0.1, and 3.0.2.
4
What type of vulnerability is CVE-2012-2398?
CVE-2012-2398 is a cross-site scripting (XSS) vulnerability.
5
Can CVE-2012-2398 lead to data theft?
Yes, exploiting CVE-2012-2398 can potentially allow attackers to inject arbitrary web scripts, leading to data theft.