Description
The public share controller in the ownCloud server before version 10.8.0 allows a remote attacker to see the internal path and the username of a public share by including invalid characters in the URL.
Remediation
References
Related Vulnerabilities
WordPress Plugin Email Queue by BestWebSoft Cross-Site Scripting (1.1.1)
WordPress Plugin CodeArt-Google MP3 Player Arbitrary File Disclosure (1.0.11)
PrestaShop Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2018-19126)
Drupal Improper Input Validation Vulnerability (CVE-2007-6299)
Oracle Database Server CVE-2011-2248 Vulnerability (CVE-2011-2248)