Candidate: CVE-2012-2398 PublicDate: 2012-04-20 10:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2398 http://secunia.com/advisories/48850 Description: Cross-site scripting (XSS) vulnerability in files/ajax/download.php in ownCloud before 3.0.3 allows remote attackers to inject arbitrary web script or HTML via the files parameter, a different vulnerability than CVE-2012-2269.4. Ubuntu-Description: Notes: mdeslaur> owncloud packages in Ubuntu are now empty Bugs: https://bugs.launchpad.net/ubuntu/+source/owncloud/+bug/1004379 Priority: medium Discovered-by: Assigned-to: CVSS: Patches_owncloud: upstream_owncloud: released (3.0.3) hardy_owncloud: DNE lucid_owncloud: DNE natty_owncloud: ignored (reached end-of-life) oneiric_owncloud: ignored (reached end-of-life) precise_owncloud: not-affected quantal_owncloud: not-affected (4.0.7debian-1ubuntu1) raring_owncloud: not-affected (4.0.7debian-1ubuntu1) saucy_owncloud: not-affected (4.0.7debian-1ubuntu1) trusty_owncloud: not-affected (4.0.7debian-1ubuntu1) trusty/esm_owncloud: DNE (trusty was not-affected [4.0.7debian-1ubuntu1]) utopic_owncloud: DNE vivid_owncloud: DNE wily_owncloud: DNE devel_owncloud: DNE