CVE-2015-4715: ownCloud
Medium severity, CVSS 4.9. EPSS: 1.4% chance of exploitation in the next 30 days.
The fetch function in OAuth/Curl.php in Dropbox-PHP, as used in ownCloud Server before 6.0.8, 7.x before 7.0.6, and 8.x before 8.0.4 when an external Dropbox storage has been mounted, allows remote administrators of Dropbox.com to read arbitrary files via an @ (at sign) character in unspecified POST values.
Affected products
- ownCloud ownCloud: before 6.0.8 (fixed in 6.0.8)
- ownCloud ownCloud Server: from 7.0.0, before 7.0.6 (fixed in 7.0.6); from 8.0.0, before 8.0.4 (fixed in 8.0.4)
Published 2020-02-17. Last modified 2026-06-17.