Description
Command injection in `main/lp/openoffice_text_document.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to upload Learning Paths to obtain remote code execution via improper neutralisation of special characters.
Remediation
References
Related Vulnerabilities
MySQL CVE-2013-3798 Vulnerability (CVE-2013-3798)
WordPress Plugin Zingiri Web Shop Cookie Multiple SQL Injection Vulnerabilities (2.4.7)
SharePoint Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-1290)
WordPress Plugin Dynamic Widgets 'id' Parameter Cross-Site Scripting (1.5.1)