Show filters
34 Total Results
Displaying 21-30 of 34
Sort by:
Attacker Value
Unknown

CVE-2018-10306

Disclosure Date: May 18, 2018 (last updated November 26, 2024)
Services/Form/classes/class.ilDateDurationInputGUI.php and Services/Form/classes/class.ilDateTimeInputGUI.php in ILIAS 5.1.x through 5.3.x before 5.3.4 allow XSS via an invalid date.
0
Attacker Value
Unknown

CVE-2018-11120

Disclosure Date: May 17, 2018 (last updated November 26, 2024)
Services/COPage/classes/class.ilPCSourceCode.php in ILIAS 5.1.x, 5.2.x, and 5.3.x before 5.3.5 has XSS.
0
Attacker Value
Unknown

CVE-2018-11117

Disclosure Date: May 17, 2018 (last updated November 26, 2024)
Services/Feeds/classes/class.ilExternalFeedItem.php in ILIAS 5.1.x, 5.2.x, and 5.3.x before 5.3.5 has XSS via a link attribute.
0
Attacker Value
Unknown

CVE-2018-11118

Disclosure Date: May 17, 2018 (last updated November 26, 2024)
The RSS subsystem in ILIAS 5.1.x, 5.2.x, and 5.3.x before 5.3.5 has XSS via a URI to Services/Feeds/classes/class.ilExternalFeedItem.php.
0
Attacker Value
Unknown

CVE-2018-11119

Disclosure Date: May 17, 2018 (last updated November 26, 2024)
ILIAS 5.1.x, 5.2.x, and 5.3.x before 5.3.5 redirects a logged-in user to a third-party site via the return_to_url parameter.
0
Attacker Value
Unknown

CVE-2018-10665

Disclosure Date: May 02, 2018 (last updated November 26, 2024)
ILIAS 5.3.4 has XSS through unsanitized output of PHP_SELF, related to shib_logout.php and third-party demo files.
0
Attacker Value
Unknown

CVE-2018-5688

Disclosure Date: January 14, 2018 (last updated November 26, 2024)
ILIAS before 5.2.4 has XSS via the cmd parameter to the displayHeader function in setup/classes/class.ilSetupGUI.php in the Setup component.
0
Attacker Value
Unknown

CVE-2017-15538

Disclosure Date: October 17, 2017 (last updated November 26, 2024)
Stored XSS vulnerability in the Media Objects component of ILIAS before 5.1.21 and 5.2.x before 5.2.9 allows an authenticated user to inject JavaScript to gain administrator privileges, related to the setParameter function in Services/MediaObjects/classes/class.ilMediaItem.php.
0
Attacker Value
Unknown

CVE-2017-7583

Disclosure Date: April 07, 2017 (last updated November 26, 2024)
ILIAS before 5.2.3 has XSS via SVG documents.
0
Attacker Value
Unknown

CVE-2014-2090

Disclosure Date: March 02, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in ilias.php in ILIAS 4.4.1 allow remote authenticated users to inject arbitrary web script or HTML via the (1) tar, (2) tar_val, or (3) title parameter.
0