CVE-2015-6500: Path Traversal
Directory traversal vulnerability in ownCloud Server before 8.0.6 and 8.1.x before 8.1.1 allows remote authenticated users to list directory contents and possibly cause a denial of service (CPU consumption) via a .. (dot dot) in the dir parameter to index.php/apps/files/ajax/scan.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-6500?
CVE-2015-6500 has a moderate severity rating as it allows remote authenticated users to potentially list directory contents and cause denial of service.
How do I fix CVE-2015-6500?
To fix CVE-2015-6500, you should upgrade to ownCloud Server version 8.0.6 or 8.1.1 or later.
Which versions of ownCloud are affected by CVE-2015-6500?
CVE-2015-6500 affects ownCloud versions before 8.0.6 and 8.1.x prior to 8.1.1.
Can CVE-2015-6500 be exploited by a non-authenticated user?
CVE-2015-6500 requires authentication, so only authenticated users can exploit this vulnerability.
What impact does CVE-2015-6500 have on system performance?
CVE-2015-6500 can lead to increased CPU consumption, potentially causing denial of service.