CVE-2014-2088: Medium severity ILIAS ILIAS vulnerability
Unrestricted file upload vulnerability in ilias.php in ILIAS 4.4.1 allows remote authenticated users to execute arbitrary PHP code by using a .php filename in an uploadfiles action to the uploadFiles command, and then accessing the .php file via a direct request to a certain clientid pathname.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2088?
CVE-2014-2088 has been assigned a medium severity rating due to the potential for arbitrary code execution.
How do I fix CVE-2014-2088?
To fix CVE-2014-2088, update to the latest version of ILIAS that addresses this vulnerability.
Who is affected by CVE-2014-2088?
CVE-2014-2088 affects ILIAS version 4.4.1, allowing remote authenticated users to exploit the vulnerability.
What type of attacks can be executed via CVE-2014-2088?
CVE-2014-2088 allows attackers to upload and execute arbitrary PHP code on the server.
Is there a workaround for CVE-2014-2088 while a patch is being applied?
As a temporary workaround for CVE-2014-2088, you can disable file uploads in the ILIAS configuration until the software is updated.