Description
The public share controller in the ownCloud server before version 10.8.0 allows a remote attacker to see the internal path and the username of a public share by including invalid characters in the URL.
Remediation
References
Related Vulnerabilities
WordPress Cleartext Storage of Sensitive Information Vulnerability (CVE-2017-14990)
TYPO3 Improper Input Validation Vulnerability (CVE-2010-3716)
WordPress Plugin All-In-One Security (AIOS)-Security and Firewall Cross-Site Scripting (3.9.7)
WordPress Plugin Visitors Online by BestWebSoft Cross-Site Scripting (0.9)