The files_antivirus component prior to 1.0.0 for ownCloud allows OS Command Injection via the administration settings.
owncloud files antivirus