bugs.koha-community.orgConfirmation
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=14412 CVE-2015-4633
CRITICAL
Koha 3.20.1 - Multiple SQL Injections
Record summary
CVE-2015-4633 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
Multiple SQL injection vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow (1) remote attackers to execute arbitrary SQL commands via the number parameter to opac-tags_subject.pl in the OPAC interface or (2) remote authenticated users to execute arbitrary SQL commands via the Filter or (3) Criteria parameter to reports/borrowers_out.pl in the Staff interface.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBKoha 3.20.1 - Multiple SQL InjectionsExploitDB exploitby Raschin Tavakoli_ Bernhard Garn_ Peter Aufner & Dimitris SimosNot analyzed1 file
References
11bugs.koha-community.orgConfirmation
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=14426 koha-community.orgConfirmation
https://koha-community.org/koha-3-14-16-released koha-community.orgConfirmation
https://koha-community.org/security-release-koha-3-16-12 koha-community.orgConfirmation
https://koha-community.org/security-release-koha-3-18-8 koha-community.orgConfirmation
https://koha-community.org/security-release-koha-3-20-1 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2015-4633 packetstormsecurity.com
https://packetstormsecurity.com/files/132458/Koha-ILS-3.20.x-CSRF-XSS-Traversal-SQL-Injection.html 20150625 SBA Research Vulnerability Disclosure - Multiple Critical Vulnerabilities in Koha ILSmailing list
https://seclists.org/fulldisclosure/2015/Jun/80 37387exploit
https://www.exploit-db.com/exploits/37387 sba-research.org
https://www.sba-research.org/2015/06/24/researchers-of-sba-research-found-several-critical-security-vulnerabilities-in-the-koha-library-software-via-combinatorial-testing