ownCloud Server before 5.0.19, 6.x before 6.0.7, and 7.x before 7.0.5 allows remote authenticated users to bypass the file blacklist and upload arbitrary files via a file path with UTF-8 encoding, as demonstrated by uploading a .htaccess file.
History

Mon, 31 Mar 2025 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Owncloud owncloud Server
CPEs cpe:2.3:a:owncloud:owncloud:*:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:*:*:*:*:*:*:*:*
Vendors & Products Owncloud owncloud
Owncloud owncloud Server

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-06T05:32:21.163Z

Reserved: 2015-04-08T00:00:00

Link: CVE-2015-3013

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2015-05-08T14:59:04.573

Modified: 2025-04-12T10:46:40.837

Link: CVE-2015-3013

cve-icon Redhat

No data.