CVE-2015-3013: ownCloud Server
Medium severity, CVSS 6.0. EPSS: 1.3% chance of exploitation in the next 30 days.
ownCloud Server before 5.0.19, 6.x before 6.0.7, and 7.x before 7.0.5 allows remote authenticated users to bypass the file blacklist and upload arbitrary files via a file path with UTF-8 encoding, as demonstrated by uploading a .htaccess file.
Affected products
- ownCloud ownCloud Server: from 5.0.0, before 5.0.19 (fixed in 5.0.19); from 6.0.0, before 6.0.7 (fixed in 6.0.7); from 7.0.0, before 7.0.5 (fixed in 7.0.5)
Published 2015-05-08. Last modified 2026-06-17.