CVE-2015-4632
Koha 3.20.1 - Directory Traversal
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
Multiple directory traversal vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow remote attackers to read arbitrary files via a ..%2f (dot dot encoded slash) in the template_path parameter to (1) svc/virtualshelves/search or (2) svc/members/search.
Múltiples vulnerabilidades Cross-Site Scripting (XSS) en Koha, en versiones 3.14.x anteriores a la 3.14.16, versiones 3.16.x anteriores a la 3.16.12, versiones 3.18.x anteriores a la 3.18.08 y versiones 3.20.x anteriores a la 3.20.1, permiten que atacantes remotos lean archivos arbitrarios mediante un ..%2f (punto punto barra cifrada) en el parámetro template_path en (1) svc/virtualshelves/search o (2) svc/members/search.
Koha ILS suffers from cross site request forgery, cross site scripting, remote SQL injection, and path traversal vulnerabilities. Versions 3.20.x less than or equal to 3.20.1, 3.18.x less than or equal to 3.18.8, and 3.16.x less than or equal to 3.16.12 are affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-06-16 CVE Reserved
- 2015-06-26 CVE Published
- 2015-06-26 First Exploit
- 2024-08-06 CVE Updated
- 2025-01-21 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (10)
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/132458 | 2015-06-26 | |
https://www.exploit-db.com/exploits/37388 | 2024-08-06 | |
https://packetstormsecurity.com/files/132458/Koha-ILS-3.20.x-CSRF-XSS-Traversal-SQL-Injection.html | 2024-08-06 |
URL | Date | SRC |
---|---|---|
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=14408 | 2018-12-31 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Koha Search vendor "Koha" | Koha Search vendor "Koha" for product "Koha" | >= 3.14.00 < 3.14.16 Search vendor "Koha" for product "Koha" and version " >= 3.14.00 < 3.14.16" | - |
Affected
| ||||||
Koha Search vendor "Koha" | Koha Search vendor "Koha" for product "Koha" | >= 3.16.00 < 3.16.12 Search vendor "Koha" for product "Koha" and version " >= 3.16.00 < 3.16.12" | - |
Affected
| ||||||
Koha Search vendor "Koha" | Koha Search vendor "Koha" for product "Koha" | >= 3.18.00 < 3.18.08 Search vendor "Koha" for product "Koha" and version " >= 3.18.00 < 3.18.08" | - |
Affected
| ||||||
Koha Search vendor "Koha" | Koha Search vendor "Koha" for product "Koha" | >= 3.20.00 < 3.20.01 Search vendor "Koha" for product "Koha" and version " >= 3.20.00 < 3.20.01" | - |
Affected
|