CVE-2011-4715: Path Traversal
Directory traversal vulnerability in cgi-bin/koha/mainpage.pl in Koha 3.4 before 3.4.7 and 3.6 before 3.6.1, and LibLime Koha 4.2 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the KohaOpacLanguage cookie to cgi-bin/opac/opac-main.pl, related to Output.pm.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4715?
CVE-2011-4715 is considered a high severity vulnerability due to its ability to allow remote attackers to read arbitrary files.
How do I fix CVE-2011-4715?
To fix CVE-2011-4715, upgrade your Koha installation to version 3.4.7 or later or 3.6.1 or later.
What systems are affected by CVE-2011-4715?
CVE-2011-4715 affects Koha versions below 3.4.7, 3.6 below 3.6.1, and all versions of LibLime Koha up to 4.2.
What type of attack can be executed using CVE-2011-4715?
CVE-2011-4715 can be exploited to perform directory traversal attacks, which allow unauthorized access to file system data.
Is there a patch available for CVE-2011-4715?
Yes, the vulnerability can be mitigated by applying the available updates for the affected Koha versions.