{"containers":{"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 4.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) file names to apps/user_ldap/settings.php; (2) url or (3) title parameter to apps/bookmarks/ajax/editBookmark.php; (4) tag or (5) page parameter to apps/bookmarks/ajax/updateList.php; (6) identity to apps/user_openid/settings.php; (7) stack name in apps/gallery/lib/tiles.php; (8) root parameter to apps/gallery/templates/index.php; (9) calendar displayname in apps/calendar/templates/part.import.php; (10) calendar uri in apps/calendar/templates/part.choosecalendar.rowfields.php; (11) title, (12) location, or (13) description parameter in apps/calendar/lib/object.php; (14) certain vectors in core/js/multiselect.js; or (15) artist, (16) album, or (17) title comments parameter in apps/media/lib_scanner.php."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2012-09-05T23:00:00.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"https://github.com/owncloud/core/commit/f8337c9d723039760eecccf68bcb02752551e254"},{"tags":["x_refsource_CONFIRM"],"url":"https://github.com/owncloud/core/commit/8f616ecf76aac4a8b554fbf5a90b1645d0f25438"},{"tags":["x_refsource_CONFIRM"],"url":"https://github.com/owncloud/core/commit/8f09299e2468dfc4f9ec72b05acf47de3ef9d1d7"},{"tags":["x_refsource_CONFIRM"],"url":"https://github.com/owncloud/core/commit/e817504569dce49fd7a677fa510e500394af0c48"},{"name":"[oss-security] 20120810 ownCloud - matching CVEs to fix information and vice versa","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2012/08/11/1"},{"tags":["x_refsource_CONFIRM"],"url":"https://github.com/owncloud/core/commit/d294373f476c795aaee7dc2444e7edfdea01a606"},{"name":"[oss-security] 20120901 Re: CVE - ownCloud","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2012/09/02/2"},{"tags":["x_refsource_CONFIRM"],"url":"https://github.com/owncloud/core/commit/642e7ce110cb8c320072532c29abe003385d50f5"},{"tags":["x_refsource_CONFIRM"],"url":"https://github.com/owncloud/core/commit/cc653a8a408adfb4d0cd532145668aacd85ad96c"},{"tags":["x_refsource_CONFIRM"],"url":"https://github.com/owncloud/core/commit/f955f6a6857754826af8903475688ba54f72c1bb"},{"tags":["x_refsource_CONFIRM"],"url":"https://github.com/owncloud/core/commit/44260a552cd4ee50ee11eee45164c725f56f7027"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"secalert@redhat.com","ID":"CVE-2012-4396","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 4.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) file names to apps/user_ldap/settings.php; (2) url or (3) title parameter to apps/bookmarks/ajax/editBookmark.php; (4) tag or (5) page parameter to apps/bookmarks/ajax/updateList.php; (6) identity to apps/user_openid/settings.php; (7) stack name in apps/gallery/lib/tiles.php; (8) root parameter to apps/gallery/templates/index.php; (9) calendar displayname in apps/calendar/templates/part.import.php; (10) calendar uri in apps/calendar/templates/part.choosecalendar.rowfields.php; (11) title, (12) location, or (13) description parameter in apps/calendar/lib/object.php; (14) certain vectors in core/js/multiselect.js; or (15) artist, (16) album, or (17) title comments parameter in apps/media/lib_scanner.php."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://github.com/owncloud/core/commit/f8337c9d723039760eecccf68bcb02752551e254","refsource":"CONFIRM","url":"https://github.com/owncloud/core/commit/f8337c9d723039760eecccf68bcb02752551e254"},{"name":"https://github.com/owncloud/core/commit/8f616ecf76aac4a8b554fbf5a90b1645d0f25438","refsource":"CONFIRM","url":"https://github.com/owncloud/core/commit/8f616ecf76aac4a8b554fbf5a90b1645d0f25438"},{"name":"https://github.com/owncloud/core/commit/8f09299e2468dfc4f9ec72b05acf47de3ef9d1d7","refsource":"CONFIRM","url":"https://github.com/owncloud/core/commit/8f09299e2468dfc4f9ec72b05acf47de3ef9d1d7"},{"name":"https://github.com/owncloud/core/commit/e817504569dce49fd7a677fa510e500394af0c48","refsource":"CONFIRM","url":"https://github.com/owncloud/core/commit/e817504569dce49fd7a677fa510e500394af0c48"},{"name":"[oss-security] 20120810 ownCloud - matching CVEs to fix information and vice versa","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2012/08/11/1"},{"name":"https://github.com/owncloud/core/commit/d294373f476c795aaee7dc2444e7edfdea01a606","refsource":"CONFIRM","url":"https://github.com/owncloud/core/commit/d294373f476c795aaee7dc2444e7edfdea01a606"},{"name":"[oss-security] 20120901 Re: CVE - ownCloud","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2012/09/02/2"},{"name":"https://github.com/owncloud/core/commit/642e7ce110cb8c320072532c29abe003385d50f5","refsource":"CONFIRM","url":"https://github.com/owncloud/core/commit/642e7ce110cb8c320072532c29abe003385d50f5"},{"name":"https://github.com/owncloud/core/commit/cc653a8a408adfb4d0cd532145668aacd85ad96c","refsource":"CONFIRM","url":"https://github.com/owncloud/core/commit/cc653a8a408adfb4d0cd532145668aacd85ad96c"},{"name":"https://github.com/owncloud/core/commit/f955f6a6857754826af8903475688ba54f72c1bb","refsource":"CONFIRM","url":"https://github.com/owncloud/core/commit/f955f6a6857754826af8903475688ba54f72c1bb"},{"name":"https://github.com/owncloud/core/commit/44260a552cd4ee50ee11eee45164c725f56f7027","refsource":"CONFIRM","url":"https://github.com/owncloud/core/commit/44260a552cd4ee50ee11eee45164c725f56f7027"}]}}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-06T20:35:09.177Z"},"title":"CVE Program Container","references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://github.com/owncloud/core/commit/f8337c9d723039760eecccf68bcb02752551e254"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://github.com/owncloud/core/commit/8f616ecf76aac4a8b554fbf5a90b1645d0f25438"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://github.com/owncloud/core/commit/8f09299e2468dfc4f9ec72b05acf47de3ef9d1d7"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://github.com/owncloud/core/commit/e817504569dce49fd7a677fa510e500394af0c48"},{"name":"[oss-security] 20120810 ownCloud - matching CVEs to fix information and vice versa","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2012/08/11/1"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://github.com/owncloud/core/commit/d294373f476c795aaee7dc2444e7edfdea01a606"},{"name":"[oss-security] 20120901 Re: CVE - ownCloud","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2012/09/02/2"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://github.com/owncloud/core/commit/642e7ce110cb8c320072532c29abe003385d50f5"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://github.com/owncloud/core/commit/cc653a8a408adfb4d0cd532145668aacd85ad96c"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://github.com/owncloud/core/commit/f955f6a6857754826af8903475688ba54f72c1bb"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://github.com/owncloud/core/commit/44260a552cd4ee50ee11eee45164c725f56f7027"}]}]},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2012-4396","datePublished":"2012-09-05T23:00:00.000Z","dateReserved":"2012-08-21T00:00:00.000Z","dateUpdated":"2024-09-17T03:14:34.442Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"}