Description
Session fixation on password protected public links in the ownCloud Server before 10.8.0 allows an attacker to bypass the password protection when they can force a target client to use a controlled cookie.
Remediation
References
Related Vulnerabilities
WordPress Plugin Google +1 by BestWebSoft Cross-Site Scripting (1.1.6)
WordPress 4.1.x Multiple Vulnerabilities (4.1 - 4.1.39)
WordPress Plugin Simple Download Button Shortcode 'file' Parameter Information Disclosure (1.0)
PHP Safedir restriction bypass vulnerabilities
WordPress Plugin Zotpress 'citation' Parameter Cross-Site Scripting (2.6.1)