VYPR
Unrated severityNVD Advisory· Published Dec 8, 2011· Updated Apr 29, 2026

CVE-2011-4715

CVE-2011-4715

Description

Directory traversal vulnerability in cgi-bin/koha/mainpage.pl in Koha 3.4 before 3.4.7 and 3.6 before 3.6.1, and LibLime Koha 4.2 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the KohaOpacLanguage cookie to cgi-bin/opac/opac-main.pl, related to Output.pm.

Affected products

9
  • Koha/Koha8 versions
    cpe:2.3:a:koha:koha:3.04.00:*:*:*:*:*:*:*+ 7 more
    • cpe:2.3:a:koha:koha:3.04.00:*:*:*:*:*:*:*
    • cpe:2.3:a:koha:koha:3.04.01:*:*:*:*:*:*:*
    • cpe:2.3:a:koha:koha:3.04.02:*:*:*:*:*:*:*
    • cpe:2.3:a:koha:koha:3.04.03:*:*:*:*:*:*:*
    • cpe:2.3:a:koha:koha:3.04.04:*:*:*:*:*:*:*
    • cpe:2.3:a:koha:koha:3.04.05:*:*:*:*:*:*:*
    • cpe:2.3:a:koha:koha:3.04.06:*:*:*:*:*:*:*
    • cpe:2.3:a:koha:koha:3.06.00.000:*:*:*:*:*:*:*
  • cpe:2.3:a:koha:liblime_koha:*:*:*:*:*:*:*:*
    Range: <=4.2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

9

News mentions

0

No linked articles in our index yet.