CVE-2014-2089: Code Injection
Published Mar 2, 2014
·Updated
ILIAS 4.4.1 allows remote attackers to execute arbitrary PHP code via an e-mail attachment that leads to creation of a .php file with a certain clientid pathname.
Affected Software
1 affected component
ILIAS ILIAS=4.4.1
Event History
Mar 2, 2014
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:55 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-2089?
CVE-2014-2089 has a high severity rating due to the potential for remote code execution.
2
How do I fix CVE-2014-2089?
To fix CVE-2014-2089, update ILIAS to the latest version that addresses this vulnerability.
3
What versions are affected by CVE-2014-2089?
CVE-2014-2089 specifically affects ILIAS version 4.4.1.
4
Can CVE-2014-2089 lead to unauthorized access?
Yes, CVE-2014-2089 can allow attackers to execute arbitrary PHP code, potentially leading to unauthorized access.
5
What type of attack does CVE-2014-2089 exploit?
CVE-2014-2089 exploits remote code execution through malicious email attachments.