Show filters
34 Total Results
Displaying 21-30 of 34
Sort by:
Attacker Value
Unknown
CVE-2018-10306
Disclosure Date: May 18, 2018 (last updated November 26, 2024)
Services/Form/classes/class.ilDateDurationInputGUI.php and Services/Form/classes/class.ilDateTimeInputGUI.php in ILIAS 5.1.x through 5.3.x before 5.3.4 allow XSS via an invalid date.
0
Attacker Value
Unknown
CVE-2018-11120
Disclosure Date: May 17, 2018 (last updated November 26, 2024)
Services/COPage/classes/class.ilPCSourceCode.php in ILIAS 5.1.x, 5.2.x, and 5.3.x before 5.3.5 has XSS.
0
Attacker Value
Unknown
CVE-2018-11117
Disclosure Date: May 17, 2018 (last updated November 26, 2024)
Services/Feeds/classes/class.ilExternalFeedItem.php in ILIAS 5.1.x, 5.2.x, and 5.3.x before 5.3.5 has XSS via a link attribute.
0
Attacker Value
Unknown
CVE-2018-11118
Disclosure Date: May 17, 2018 (last updated November 26, 2024)
The RSS subsystem in ILIAS 5.1.x, 5.2.x, and 5.3.x before 5.3.5 has XSS via a URI to Services/Feeds/classes/class.ilExternalFeedItem.php.
0
Attacker Value
Unknown
CVE-2018-11119
Disclosure Date: May 17, 2018 (last updated November 26, 2024)
ILIAS 5.1.x, 5.2.x, and 5.3.x before 5.3.5 redirects a logged-in user to a third-party site via the return_to_url parameter.
0
Attacker Value
Unknown
CVE-2018-10665
Disclosure Date: May 02, 2018 (last updated November 26, 2024)
ILIAS 5.3.4 has XSS through unsanitized output of PHP_SELF, related to shib_logout.php and third-party demo files.
0
Attacker Value
Unknown
CVE-2018-5688
Disclosure Date: January 14, 2018 (last updated November 26, 2024)
ILIAS before 5.2.4 has XSS via the cmd parameter to the displayHeader function in setup/classes/class.ilSetupGUI.php in the Setup component.
0
Attacker Value
Unknown
CVE-2017-15538
Disclosure Date: October 17, 2017 (last updated November 26, 2024)
Stored XSS vulnerability in the Media Objects component of ILIAS before 5.1.21 and 5.2.x before 5.2.9 allows an authenticated user to inject JavaScript to gain administrator privileges, related to the setParameter function in Services/MediaObjects/classes/class.ilMediaItem.php.
0
Attacker Value
Unknown
CVE-2017-7583
Disclosure Date: April 07, 2017 (last updated November 26, 2024)
ILIAS before 5.2.3 has XSS via SVG documents.
0
Attacker Value
Unknown
CVE-2014-2090
Disclosure Date: March 02, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in ilias.php in ILIAS 4.4.1 allow remote authenticated users to inject arbitrary web script or HTML via the (1) tar, (2) tar_val, or (3) title parameter.
0