ownCloud Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) Vulnerability - CVE-2015-4718
The external SMB storage driver in ownCloud Server before 6.0.8 7.0.x before 7.0.6 and 8.0.x before 8.0.4 allows remote authenticated users to execute arbitrary SMB commands via a (semicolon) character in a file.