First published: Tue Dec 18 2012(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 4.0.9 and 4.5.0 allow remote attackers to inject arbitrary web script or HTML via the (1) file name to apps/files_versions/js/versions.js or (2) apps/files/js/filelist.js; or (3) event title to 3rdparty/fullcalendar/js/fullcalendar.js.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
ownCloud | <=4.0.8 | |
ownCloud | =3.0.0 | |
ownCloud | =3.0.1 | |
ownCloud | =3.0.2 | |
ownCloud | =3.0.3 | |
ownCloud | =4.0.0 | |
ownCloud | =4.0.1 | |
ownCloud | =4.0.2 | |
ownCloud | =4.0.3 | |
ownCloud | =4.0.4 | |
ownCloud | =4.0.5 | |
ownCloud | =4.0.6 | |
ownCloud | =4.0.7 | |
ownCloud | =4.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-5606 is rated as a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2012-5606, upgrade ownCloud to version 4.0.9 or later, or 4.5.0 or later.
CVE-2012-5606 can facilitate remote cross-site scripting (XSS) attacks by allowing attackers to inject arbitrary web scripts.
CVE-2012-5606 affects ownCloud versions before 4.0.9 and specific versions in the 3.x range up to 4.5.0.
Key components involved in CVE-2012-5606 include the files_versions.js and filelist.js scripts, along with event titles in the fullcalendar component.