Record summary

CVE-2015-4633 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.

Description

Multiple SQL injection vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow (1) remote attackers to execute arbitrary SQL commands via the number parameter to opac-tags_subject.pl in the OPAC interface or (2) remote authenticated users to execute arbitrary SQL commands via the Filter or (3) Criteria parameter to reports/borrowers_out.pl in the Staff interface.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBKoha 3.20.1 - Multiple SQL InjectionsExploitDB exploitby Raschin Tavakoli_ Bernhard Garn_ Peter Aufner & Dimitris SimosNot analyzed1 file
ExploitDB

PoC details

References

11