Description
The documents application in ownCloud Server 6.x before 6.0.6 and 7.x before 7.0.3 allows remote authenticated users to obtain all valid session IDs via an unspecified API method.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP RSS By Publishers Multiple SQL Injection Vulnerabilities (0.1)
PHP Missing Release of Resource after Effective Lifetime Vulnerability (CVE-2010-4657)
Drupal Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-3742)
PHP Integer Overflow or Wraparound Vulnerability (CVE-2015-2305)