PT-2014-4477 · Ilias Open Source E Learning Platform · Ilias

Published

2014-03-02

·

Updated

2014-03-03

·

CVE-2014-2089

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ILIAS version 4.4.1
Description The issue allows remote attackers to execute arbitrary PHP code via an e-mail attachment. This attachment leads to the creation of a .php file with a certain client id pathname.
Recommendations For ILIAS version 4.4.1, update to a newer version that contains a fix for this issue to prevent the execution of arbitrary PHP code.

Exploit

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-2089

Affected Products

Ilias