CVE-2007-5806

ILIAS <3.8.3 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in Services/Utilities/classes/class.ilUtil.php in ILIAS 3.8.3 and earlier allows remote attackers to inject arbitrary web script or HTML via attributes inside a domain-name string in the (1) mailing or (2) forum component, as demonstrated using the style and onmouseover HTML attributes.

Scores

EPSS 0.0054
EPSS Percentile 67.2%

Classification

CWE
CWE-79
Status draft

Affected Products (4)

ilias/ilias < 3.8.3
ilias/ilias
ilias/ilias
ilias/ilias

Timeline

Published Nov 05, 2007
Tracked Since Feb 18, 2026