Total
26 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2018-10665 | 1 Ilias | 1 Ilias | 2018-06-07 | 4.3 MEDIUM | 6.1 MEDIUM |
ILIAS 5.3.4 has XSS through unsanitized output of PHP_SELF, related to shib_logout.php and third-party demo files. | |||||
CVE-2018-5688 | 1 Ilias | 1 Ilias | 2018-02-05 | 4.3 MEDIUM | 6.1 MEDIUM |
ILIAS before 5.2.4 has XSS via the cmd parameter to the displayHeader function in setup/classes/class.ilSetupGUI.php in the Setup component. | |||||
CVE-2008-5816 | 1 Ilias | 1 Ilias | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in repository.php in ILIAS 3.7.4 and earlier allows remote attackers to execute arbitrary SQL commands via the ref_id parameter. | |||||
CVE-2014-2090 | 1 Ilias | 1 Ilias | 2014-03-03 | 3.5 LOW | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in ilias.php in ILIAS 4.4.1 allow remote authenticated users to inject arbitrary web script or HTML via the (1) tar, (2) tar_val, or (3) title parameter. | |||||
CVE-2014-2089 | 1 Ilias | 1 Ilias | 2014-03-03 | 6.8 MEDIUM | N/A |
ILIAS 4.4.1 allows remote attackers to execute arbitrary PHP code via an e-mail attachment that leads to creation of a .php file with a certain client_id pathname. | |||||
CVE-2014-2088 | 1 Ilias | 1 Ilias | 2014-03-03 | 6.5 MEDIUM | N/A |
Unrestricted file upload vulnerability in ilias.php in ILIAS 4.4.1 allows remote authenticated users to execute arbitrary PHP code by using a .php filename in an upload_files action to the uploadFiles command, and then accessing the .php file via a direct request to a certain client_id pathname. |