CVE-2015-6500: ownCloud Server

High severity, CVSS 7.5. EPSS: 2.6% chance of exploitation in the next 30 days.

Directory traversal vulnerability in ownCloud Server before 8.0.6 and 8.1.x before 8.1.1 allows remote authenticated users to list directory contents and possibly cause a denial of service (CPU consumption) via a .. (dot dot) in the dir parameter to index.php/apps/files/ajax/scan.php.

Affected products

  • ownCloud ownCloud Server: version 7.0.0 only; version 7.0.1 only; version 7.0.2 only; version 7.0.3 only; version 7.0.4 only; version 7.0.5 only; …

Published 2015-10-26. Last modified 2026-06-17.