CVE-2014-4929: ownCloud

Medium severity, CVSS 6.8. EPSS: 2.3% chance of exploitation in the next 30 days.

Directory traversal vulnerability in the routing component in ownCloud Server before 5.0.17 and 6.0.x before 6.0.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in a filename, related to index.php.

Affected products

  • ownCloud ownCloud: up to and including 5.0.16
  • ownCloud ownCloud Server: version 6.0.0 only; version 6.0.1 only; version 6.0.2 only; version 6.0.3 only; version 5.0.0 only; version 5.0.1 only; …

Published 2014-08-20. Last modified 2026-06-17.