Description
Session fixation on password protected public links in the ownCloud Server before 10.8.0 allows an attacker to bypass the password protection when they can force a target client to use a controlled cookie.
Remediation
References
Related Vulnerabilities
PHP CVE-2009-3559 Vulnerability (CVE-2009-3559)
WebLogic CVE-2019-2645 Vulnerability (CVE-2019-2645)
MediaWiki Improper Access Control Vulnerability (CVE-2016-6331)
Apache HTTP Server NULL Pointer Dereference Vulnerability (CVE-2020-13950)
WordPress Plugin WooCommerce BuddyPress Integration Security Bypass (3.2.5)