CVE-2012-4396
Last modified
CVE-2012-4396 is a vulnerability of currently unknown severity. Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 4.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) file names to apps/user_ldap/settings.php; (2) url or (3) title parameter to apps/bookmarks/ajax/editBookmark.php; (4) tag or (5) page parameter to apps/bookmarks/ajax/updateList.php; (6) identity to apps/user_openid/settings.php; (7) stack name in apps/gallery/lib/tiles.php; (8) root parameter to apps/gallery/templates/index.php; (9) calendar displayname in apps/calendar/templates/part.import.php; (10) calendar uri in apps/calendar/templates/part.choosecalendar.rowfields.php; (11) title, (12) location, or (13) description parameter in apps/calendar/lib/object.php; (14) certain vectors in core/js/multiselect.js; or (15) artist, (16) album, or (17) title comments parameter in apps/media/lib_scanner.php.. EPSS estimates a 2.48% chance of exploitation in the next 30 days.
Description
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 4.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) file names to apps/user_ldap/settings.php; (2) url or (3) title parameter to apps/bookmarks/ajax/editBookmark.php; (4) tag or (5) page parameter to apps/bookmarks/ajax/updateList.php; (6) identity to apps/user_openid/settings.php; (7) stack name in apps/gallery/lib/tiles.php; (8) root parameter to apps/gallery/templates/index.php; (9) calendar displayname in apps/calendar/templates/part.import.php; (10) calendar uri in apps/calendar/templates/part.choosecalendar.rowfields.php; (11) title, (12) location, or (13) description parameter in apps/calendar/lib/object.php; (14) certain vectors in core/js/multiselect.js; or (15) artist, (16) album, or (17) title comments parameter in apps/media/lib_scanner.php.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Owncloud | Owncloud | <= 4.0.1 |
| Owncloud | Owncloud Server | 3.0.0 |
| Owncloud | Owncloud Server | 3.0.1 |
| Owncloud | Owncloud Server | 3.0.2 |
| Owncloud | Owncloud Server | 3.0.3 |
| Owncloud | Owncloud Server | 4.0.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-4396?
How severe is CVE-2012-4396?
How do I fix CVE-2012-4396?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2012
- CVE-2012-4390(1) apps/calendar/appinfo/remote.php and (2) apps/contacts/a…
- CVE-2012-4391Cross-site request forgery (CSRF) vulnerability in core/ajax…
- CVE-2012-4392index.php in ownCloud 4.0.7 does not properly validate the o…
- CVE-2012-4393Multiple cross-site request forgery (CSRF) vulnerabilities i…
- CVE-2012-4394Cross-site scripting (XSS) vulnerability in apps/files/js/fi…
- CVE-2012-4395Cross-site scripting (XSS) vulnerability in index.php in own…
- CVE-2012-4397Multiple cross-site scripting (XSS) vulnerabilities in ownCl…
- CVE-2012-4398The __request_module function in kernel/kmod.c in the Linux …
- CVE-2012-4399The Xml class in CakePHP 2.1.x before 2.1.5 and 2.2.x before…7.5
- CVE-2012-4400repository/repository_ajax.php in Moodle 2.2.x before 2.2.5 …
- CVE-2012-4401Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remo…
- CVE-2012-4402webservice/lib.php in Moodle 2.1.x before 2.1.8, 2.2.x befor…
Are you affected by CVE-2012-4396?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
