Candidate: CVE-2013-0203 PublicDate: 2019-11-22 19:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0203 http://www.openwall.com/lists/oss-security/2013/01/22 http://owncloud.org/about/security/advisories/oC-SA-2013-001/ Description: Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 4.5.5, 4.0.10, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) unspecified parameters to apps/calendar/ajax/event/new.php or (2) url parameter to apps/bookmarks/ajax/addBookmark.php. Ubuntu-Description: Notes: mdeslaur> owncloud packages in Ubuntu are now empty seth-arnold> I don't know where the repository is, but the checkins seth-arnold> are 708bd and 3f37063 Bugs: Priority: medium Discovered-by: Frans Rosén Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N [5.4 MEDIUM] Patches_owncloud: upstream_owncloud: released (4.0.11) hardy_owncloud: DNE lucid_owncloud: DNE oneiric_owncloud: ignored (reached end-of-life) precise_owncloud: not-affected quantal_owncloud: ignored (reached end-of-life) raring_owncloud: not-affected (5.0.4debian-0ubuntu1) saucy_owncloud: not-affected (5.0.4debian-0ubuntu1) trusty_owncloud: not-affected (5.0.4debian-0ubuntu1) trusty/esm_owncloud: DNE (trusty was not-affected [5.0.4debian-0ubuntu1]) utopic_owncloud: DNE vivid_owncloud: DNE wily_owncloud: DNE devel_owncloud: DNE