3.5
CVSSv2

CVE-2014-2090

Published: 02/03/2014 Updated: 03/03/2014
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
VMScore: 355
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in ilias.php in ILIAS 4.4.1 allow remote authenticated users to inject arbitrary web script or HTML via the (1) tar, (2) tar_val, or (3) title parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

ilias ilias 4.4.1

Exploits

# ============================================================== # Title | Multiple vulnerabilities in ILIAS # Version | ilias-441zip # Date | 21022014 # Found | HauntIT Blog # Home | wwwiliasde # ============================================================== First from admin user logged in: # =============================== ...