ownCloud Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2013-1893 - Vulnerability Database

ownCloud Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2013-1893

Medium
Reference: CVE-2013-1893
Title: ownCloud Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
Overview:

SQL injection vulnerability in addressbookprovider.php in ownCloud Server before 5.0.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors related to the contacts application.