Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2015-4632 PoC — Koha 路径遍历漏洞

Source
Associated Vulnerability
Title:Koha 路径遍历漏洞 (CVE-2015-4632)
Description:Koha是Koha社区开发的一套开源的图书馆自动化系统(ILS)。该系统提供分类、检索、成员和顾客管理等功能。 Koha中存在多个目录遍历漏洞。远程攻击者可通过向svc/virtualshelves/search或svc/members/search页面发送带有..%2f的‘template_path’参数利用该漏洞读取任意文件。以下版本受到影响:Koha 3.14.16之前的3.14.x版本,3.16.12之前的3.16.x版本,3.18.08之前的3.18.x版本,3.20.1之前的3.20.x版本。
Description
Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow remote attackers to read arbitrary files via a ..%2f (dot dot encoded slash) in the template_path parameter to (1) svc/virtualshelves/search or (2) svc/members/search.
File Snapshot

id: CVE-2015-4632 info: name: Koha 3.20.1 - Directory Traversal author: daffainfo severity: h ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.