CVE-2011-4715

Koha < 3.4.7 and 3.6 < 3.6.1 and LibLime Koha < 4.2 - Path Traversal via KohaOpacLanguage Cookie

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2011-4715. PoCs published by Akin Tosunlar.

AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in Koha Opac versions prior to 4.2. The attack manipulates the 'KohaOpacLanguage' cookie to include arbitrary files (e.g., /etc/passwd) via directory traversal sequences.

Description

Directory traversal vulnerability in cgi-bin/koha/mainpage.pl in Koha 3.4 before 3.4.7 and 3.6 before 3.6.1, and LibLime Koha 4.2 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the KohaOpacLanguage cookie to cgi-bin/opac/opac-main.pl, related to Output.pm.

Exploits (1)

exploitdb WORKING POC
by Akin Tosunlar · textwebappscgi
https://www.exploit-db.com/exploits/18153

This exploit demonstrates a Local File Inclusion (LFI) vulnerability in Koha Opac versions prior to 4.2. The attack manipulates the 'KohaOpacLanguage' cookie to include arbitrary files (e.g., /etc/passwd) via directory traversal sequences.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Koha Opac <4.2
No auth needed
Prerequisites: Target running Koha Opac <4.2 · Access to the application's web interface
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (9)

Core 9
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/50812
Various Sources x_refsource_confirm
http://koha-community.org/koha-3-6-1/#more-2929
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/18153
Various Sources x_refsource_confirm
http://koha-community.org/koha-3-4-7/#more-2971
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/77322
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/46980
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/71478

Scores

EPSS 0.0938
EPSS Percentile 94.8%

Details

CWE
CWE-22
Status published
Products (9)
koha/koha 3.06.00.000
koha/koha 3.04.00
koha/koha 3.04.01
koha/koha 3.04.02
koha/koha 3.04.03
koha/koha 3.04.04
koha/koha 3.04.05
koha/koha 3.04.06
koha/liblime_koha < 4.2
Published Dec 08, 2011
Tracked Since Feb 18, 2026