CVE-2011-4715

Directory traversal vulnerability in cgi-bin/koha/mainpage.pl in Koha 3.4 before 3.4.7 and 3.6 before 3.6.1, and LibLime Koha 4.2 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the KohaOpacLanguage cookie to cgi-bin/opac/opac-main.pl, related to Output.pm.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 95%
VendorProductVersion
kohaliblime_koha
𝑥
≤ 4.2
kohakoha
3.06.00.000
kohakoha
3.04.00
kohakoha
3.04.01
kohakoha
3.04.02
kohakoha
3.04.03
kohakoha
3.04.04
kohakoha
3.04.05
kohakoha
3.04.06
𝑥
= Vulnerable software versions