CVE-2014-2088
02.03.2014, 17:55
Unrestricted file upload vulnerability in ilias.php in ILIAS 4.4.1 allows remote authenticated users to execute arbitrary PHP code by using a .php filename in an upload_files action to the uploadFiles command, and then accessing the .php file via a direct request to a certain client_id pathname.Enginsight
Vendor | Product | Version |
---|---|---|
ilias | ilias | 4.4.1 |
𝑥
= Vulnerable software versions