CVE-2011-4715
08.12.2011, 19:55
Directory traversal vulnerability in cgi-bin/koha/mainpage.pl in Koha 3.4 before 3.4.7 and 3.6 before 3.6.1, and LibLime Koha 4.2 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the KohaOpacLanguage cookie to cgi-bin/opac/opac-main.pl, related to Output.pm.
Vendor | Product | Version |
---|---|---|
koha | liblime_koha | 𝑥 ≤ 4.2 |
koha | koha | 3.06.00.000 |
koha | koha | 3.04.00 |
koha | koha | 3.04.01 |
koha | koha | 3.04.02 |
koha | koha | 3.04.03 |
koha | koha | 3.04.04 |
koha | koha | 3.04.05 |
koha | koha | 3.04.06 |
𝑥
= Vulnerable software versions