Vulnerabilities > Ilias > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2014-03-02 | CVE-2014-2089 | Code Injection vulnerability in Ilias 4.4.1 ILIAS 4.4.1 allows remote attackers to execute arbitrary PHP code via an e-mail attachment that leads to creation of a .php file with a certain client_id pathname. | 6.8 |
2014-03-02 | CVE-2014-2088 | Unspecified vulnerability in Ilias 4.4.1 Unrestricted file upload vulnerability in ilias.php in ILIAS 4.4.1 allows remote authenticated users to execute arbitrary PHP code by using a .php filename in an upload_files action to the uploadFiles command, and then accessing the .php file via a direct request to a certain client_id pathname. | 6.5 |
2007-11-05 | CVE-2007-5806 | Cross-Site Scripting vulnerability in Ilias Cross-site scripting (XSS) vulnerability in Services/Utilities/classes/class.ilUtil.php in ILIAS 3.8.3 and earlier allows remote attackers to inject arbitrary web script or HTML via attributes inside a domain-name string in the (1) mailing or (2) forum component, as demonstrated using the style and onmouseover HTML attributes. | 4.3 |