Description
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 4.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) calendar displayname to part.choosecalendar.rowfields.php or (2) part.choosecalendar.rowfields.shared.php in apps/calendar/templates/; or (3) unspecified vectors to apps/contacts/lib/vcard.php.
Remediation
References
Related Vulnerabilities
Apache Traffic Server CVE-2024-38311 Vulnerability (CVE-2024-38311)
WordPress Plugin JTRT Responsive Tables SQL Injection (4.1)
PHP Improper Input Validation Vulnerability (CVE-2006-6383)
PHP Integer Overflow or Wraparound Vulnerability (CVE-2016-7568)
WordPress Plugin StatPress Multiple Unspecified Vulnerabilities (1.4.1)