Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown
CVE-2014-2090
Disclosure Date: March 02, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in ilias.php in ILIAS 4.4.1 allow remote authenticated users to inject arbitrary web script or HTML via the (1) tar, (2) tar_val, or (3) title parameter.
0
Attacker Value
Unknown
CVE-2014-2088
Disclosure Date: March 02, 2014 (last updated October 05, 2023)
Unrestricted file upload vulnerability in ilias.php in ILIAS 4.4.1 allows remote authenticated users to execute arbitrary PHP code by using a .php filename in an upload_files action to the uploadFiles command, and then accessing the .php file via a direct request to a certain client_id pathname.
0
Attacker Value
Unknown
CVE-2014-2089
Disclosure Date: March 02, 2014 (last updated October 05, 2023)
ILIAS 4.4.1 allows remote attackers to execute arbitrary PHP code via an e-mail attachment that leads to creation of a .php file with a certain client_id pathname.
0