CVE-2014-1924
- EPSS 4.08%
- Veröffentlicht 24.01.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 02:05:17
The MARC framework import/export function (admin/import_export_framework.pl) in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, and 3.14.x before 3.14.3 does not require authentication, which allows remote attackers to conduct SQL i...
CVE-2014-1922
- EPSS 0.92%
- Veröffentlicht 24.01.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 02:05:16
Absolute path traversal vulnerability in tools/pdfViewer.pl in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, and 3.14.x before 3.14.3 allows remote attackers to read arbitrary files via unspecified vectors.
CVE-2015-4633
- EPSS 3.88%
- Veröffentlicht 18.10.2018 21:29:01
- Zuletzt bearbeitet 21.11.2024 02:31:26
Multiple SQL injection vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow (1) remote attackers to execute arbitrary SQL commands via the number parameter to opac-tags_subject.pl...
CVE-2015-4632
- EPSS 77.75%
- Veröffentlicht 18.10.2018 21:29:01
- Zuletzt bearbeitet 21.11.2024 02:31:26
Multiple directory traversal vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow remote attackers to read arbitrary files via a ..%2f (dot dot encoded slash) in the template_path...
CVE-2015-4631
- EPSS 0.52%
- Veröffentlicht 18.10.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 02:31:26
Multiple cross-site scripting (XSS) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow remote attackers to inject arbitrary web script or HTML via the (1) tag parameter to opac-...
- EPSS 0.64%
- Veröffentlicht 18.10.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 02:31:26
Multiple cross-site request forgery (CSRF) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow remote attackers to (1) hijack the authentication of administrators for requests th...
CVE-2018-1000670
- EPSS 0.28%
- Veröffentlicht 06.09.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:40:22
KOHA Library System version 16.11.x (up until 16.11.13) and 17.05.x (up until 17.05.05) contains a Cross Site Scripting (XSS) vulnerability in Multiple fields on multiple pages including /cgi-bin/koha/acqui/supplier.pl?op=enter , /cgi-bin/koha/circ/c...
CVE-2018-1000669
- EPSS 0.14%
- Veröffentlicht 06.09.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:40:22
KOHA Library System version 16.11.x (up until 16.11.13) and 17.05.x (up until 17.05.05) contains a Cross Site Request Forgery (CSRF) vulnerability in /cgi-bin/koha/members/paycollect.pl Parameters affected: borrowernumber, amount, amountoutstanding, ...
CVE-2015-4639
- EPSS 0.18%
- Veröffentlicht 21.07.2017 14:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cross-site scripting (XSS) vulnerability in opac-addbybiblionumber.pl in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, and 3.20.x before 3.20.1 allows remote attackers to inject arbitrary web script or HTML via a crafted list name.
CVE-2014-9446
- EPSS 0.36%
- Veröffentlicht 02.01.2015 20:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple cross-site scripting (XSS) vulnerabilities in the Staff client in Koha before 3.16.6 and 3.18.x before 3.18.2 allow remote attackers to inject arbitrary web script or HTML via the sort_by parameter to the (1) opac parameter in opac-search.pl...