ownCloud Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2013-0201 - Vulnerability Database

ownCloud Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2013-0201

Medium
Reference: CVE-2013-0201
Title: ownCloud Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 4.5.5 4.0.10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) QUERY_STRING to core/lostpassword/templates/resetpassword.php (2) mime parameter to apps/files/ajax/mimeicon.php or (3) token parameter to apps/gallery/sharing.php.