CVE-2012-4395: XSS
Published Sep 5, 2012
·Updated
Cross-site scripting (XSS) vulnerability in index.php in ownCloud before 4.0.3 allows remote attackers to inject arbitrary web script or HTML via the redirecturl parameter.
Affected Software
11 affected components
ownCloud ownCloud<=4.0.2
ownCloud ownCloud=3.0.0
ownCloud ownCloud=3.0.1
ownCloud ownCloud=3.0.2
ownCloud ownCloud=4.0.0
ownCloud ownCloud=4.0.1
ownCloud ownCloud Server=3.0.0
ownCloud ownCloud Server=3.0.1
ownCloud ownCloud Server=3.0.2
ownCloud ownCloud Server=4.0.0
ownCloud ownCloud Server=4.0.1
Remediation
Event History
Sep 5, 2012
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-4395?
The severity of CVE-2012-4395 is considered moderate due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2012-4395?
To fix CVE-2012-4395, upgrade to ownCloud version 4.0.3 or later.
3
Which versions are affected by CVE-2012-4395?
CVE-2012-4395 affects ownCloud versions prior to 4.0.3, specifically from versions 3.0.0 to 4.0.2.
4
Can CVE-2012-4395 lead to data exposure?
Yes, CVE-2012-4395 can lead to data exposure as attackers may inject malicious scripts that could access user data.
5
Is it possible to exploit CVE-2012-4395 remotely?
Yes, CVE-2012-4395 can be exploited by remote attackers through the redirect_url parameter.