CVE-2011-4715

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
08/12/2011
Last modified:
11/04/2025

Description

Directory traversal vulnerability in cgi-bin/koha/mainpage.pl in Koha 3.4 before 3.4.7 and 3.6 before 3.6.1, and LibLime Koha 4.2 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the KohaOpacLanguage cookie to cgi-bin/opac/opac-main.pl, related to Output.pm.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:koha:liblime_koha:*:*:*:*:*:*:*:* 4.2 (including)
cpe:2.3:a:koha:koha:3.06.00.000:*:*:*:*:*:*:*
cpe:2.3:a:koha:koha:3.04.00:*:*:*:*:*:*:*
cpe:2.3:a:koha:koha:3.04.01:*:*:*:*:*:*:*
cpe:2.3:a:koha:koha:3.04.02:*:*:*:*:*:*:*
cpe:2.3:a:koha:koha:3.04.03:*:*:*:*:*:*:*
cpe:2.3:a:koha:koha:3.04.04:*:*:*:*:*:*:*
cpe:2.3:a:koha:koha:3.04.05:*:*:*:*:*:*:*
cpe:2.3:a:koha:koha:3.04.06:*:*:*:*:*:*:*