Show filters
34 Total Results
Displaying 31-34 of 34
Sort by:
Attacker Value
Unknown

CVE-2014-2088

Disclosure Date: March 02, 2014 (last updated October 05, 2023)
Unrestricted file upload vulnerability in ilias.php in ILIAS 4.4.1 allows remote authenticated users to execute arbitrary PHP code by using a .php filename in an upload_files action to the uploadFiles command, and then accessing the .php file via a direct request to a certain client_id pathname.
0
Attacker Value
Unknown

CVE-2014-2089

Disclosure Date: March 02, 2014 (last updated October 05, 2023)
ILIAS 4.4.1 allows remote attackers to execute arbitrary PHP code via an e-mail attachment that leads to creation of a .php file with a certain client_id pathname.
0
Attacker Value
Unknown

CVE-2008-5816

Disclosure Date: January 02, 2009 (last updated October 04, 2023)
SQL injection vulnerability in repository.php in ILIAS 3.7.4 and earlier allows remote attackers to execute arbitrary SQL commands via the ref_id parameter.
0
Attacker Value
Unknown

CVE-2007-5806

Disclosure Date: November 05, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Services/Utilities/classes/class.ilUtil.php in ILIAS 3.8.3 and earlier allows remote attackers to inject arbitrary web script or HTML via attributes inside a domain-name string in the (1) mailing or (2) forum component, as demonstrated using the style and onmouseover HTML attributes.
0