VYPR
Unrated severityNVD Advisory· Published Mar 2, 2014· Updated Apr 29, 2026

CVE-2014-2088

CVE-2014-2088

Description

Unrestricted file upload vulnerability in ilias.php in ILIAS 4.4.1 allows remote authenticated users to execute arbitrary PHP code by using a .php filename in an upload_files action to the uploadFiles command, and then accessing the .php file via a direct request to a certain client_id pathname.

Affected products

1
  • cpe:2.3:a:ilias:ilias:4.4.1:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.