CVE-2012-5666: XSS
Published Jan 3, 2013
·Updated
Cross-site scripting (XSS) vulnerability in bookmarks/js/bookmarks.js in ownCloud 4.0.x before 4.0.10 and 4.5.x before 4.5.5 allows remote attackers to inject arbitrary web script or HTML via the PATHINFO to apps/bookmark/index.php.
Affected Software
30 affected components
ownCloud ownCloud=4.0.0
ownCloud ownCloud=4.0.1
ownCloud ownCloud=4.0.2
ownCloud ownCloud=4.0.3
ownCloud ownCloud=4.0.4
ownCloud ownCloud=4.0.5
ownCloud ownCloud=4.0.6
ownCloud ownCloud=4.0.7
ownCloud ownCloud=4.0.8
ownCloud ownCloud=4.0.9
ownCloud ownCloud=4.5.0
ownCloud ownCloud=4.5.1
ownCloud ownCloud=4.5.2
ownCloud ownCloud=4.5.3
ownCloud ownCloud=4.5.4
ownCloud ownCloud Server=4.0.0
ownCloud ownCloud Server=4.0.1
ownCloud ownCloud Server=4.0.2
ownCloud ownCloud Server=4.0.3
ownCloud ownCloud Server=4.0.4
ownCloud ownCloud Server=4.0.5
ownCloud ownCloud Server=4.0.6
ownCloud ownCloud Server=4.0.7
ownCloud ownCloud Server=4.0.8
ownCloud ownCloud Server=4.0.9
ownCloud ownCloud Server=4.5.0
ownCloud ownCloud Server=4.5.1
ownCloud ownCloud Server=4.5.2
ownCloud ownCloud Server=4.5.3
ownCloud ownCloud Server=4.5.4
Event History
Jan 3, 2013
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-5666?
CVE-2012-5666 is classified as a medium severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2012-5666?
To fix CVE-2012-5666, upgrade ownCloud to version 4.0.10 or 4.5.5 or later.
3
What software versions are affected by CVE-2012-5666?
CVE-2012-5666 affects ownCloud versions 4.0.x before 4.0.10 and 4.5.x before 4.5.5.
4
Can CVE-2012-5666 lead to data compromise?
Yes, CVE-2012-5666 can allow attackers to inject arbitrary scripts, potentially leading to data compromise.
5
Is there a risk of exploitation for web applications using ownCloud vulnerable to CVE-2012-5666?
Yes, web applications using vulnerable versions of ownCloud are at risk of exploitation through XSS attacks.