5
CVSSv2

CVE-2011-4715

Published: 08/12/2011 Updated: 29/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in cgi-bin/koha/mainpage.pl in Koha 3.4 prior to 3.4.7 and 3.6 prior to 3.6.1, and LibLime Koha 4.2 and previous versions allows remote malicious users to read arbitrary files via a .. (dot dot) in the KohaOpacLanguage cookie to cgi-bin/opac/opac-main.pl, related to Output.pm.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

koha liblime koha

koha koha 3.06.00.000

koha koha 3.04.04

koha koha 3.04.03

koha koha 3.04.02

koha koha 3.04.01

koha koha 3.04.00

koha koha 3.04.06

koha koha 3.04.05

Exploits

# Exploit Title: [Koha Opac Local File Inclusion] # Google Dork: [inurl:koha/opac-mainpl] # Date: [17112011] # Author: [Akin Tosunlar(Vigasis Labs)] # Software Link: [wwwkohaorg] # Version: [<42] # Tested on: [Linux(Apache 2214)] # CVE : [] # Vigasis Pentest Team (wwwvigasiscom) # 0-Day Exploit # Akin Tosunlar # Special Thanks t ...