Description
Command injection in `main/lp/openoffice_presentation.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to upload Learning Paths to obtain remote code execution via improper neutralisation of special characters.
Remediation
References
Related Vulnerabilities
WordPress 3.9.1 Multiple Vulnerabilities (3.9 - 3.9.1)
Apache HTTP Server Other Vulnerability (CVE-2000-0913)
WordPress Plugin U Extended Comment 'fileurl' Parameter Arbitrary File Download (1.0.1)
WordPress Plugin RoyalSlider Cross-Site Scripting (3.2.4)
Apache Tomcat Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2017-12615)