sleed Posted May 22, 2015 Report Posted May 22, 2015 Vendor: https://owncloud.comVuln.: Stored XSS + S.Q.L.iPoC:Raportat + Raspuns + H.O.F:From: Lukas Reschke <lukas@statuscode.ch>Subject: Re: [security] [XSS + SQLi] https://owncloud.comDate: May 22, 2015 at 10:36:25 AM GMT+2To: Sleed <sleed_rst@*******.com>Cc: "security@owncloud.com" <security@owncloud.com>Hi Ilca,Thank you for disclosing this vulnerability in a responsible way to us. We were able to reproduce this and have escalated this report to the website team.Meanwhile please let us know how you want to be credited on our HoF. – As soon as a fix is staged on our production instance we will add you to this page as well as get back to you with a heads-up.Thanks again!Lukas Quote