Incomplete blacklist vulnerability in ownCloud before 5.0.6 allows remote authenticated users to execute arbitrary PHP code by uploading a crafted file, then accessing it via a direct request to the file in /data. Per: https://cwe.mitre.org/data/definitions/184.html
"CWE-184: Incomplete Blacklist"
Publication date: Fri, 14 Mar 2014 21:55:00 +0000