TROYANOSYVIRUS
Voltar para CVEs

CVE-2012-4397

N/A

Descricao

Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 4.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) calendar displayname to part.choosecalendar.rowfields.php or (2) part.choosecalendar.rowfields.shared.php in apps/calendar/templates/; or (3) unspecified vectors to apps/contacts/lib/vcard.php.

Detalhes CVE

Pontuacao CVSS v3.1N/A
Publicado9/5/2012
Ultima modificacao4/11/2025
Fontenvd
Avistamentos honeypot0

Produtos afetados

owncloud:owncloudowncloud:owncloud_server

Fraquezas (CWE)

CWE-79

Correlacoes IOC

Sem correlacoes registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.