Summary
Koha is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to obtain potentially sensitive information or execute arbitrary script code in the context of the webserver process. This may allow the attacker to compromise the application and the computer
other attacks are also possible.
References
Severity
Classification
-
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities
- Adobe ColdFusion Multiple Vulnerabilities-01 May-2014
- ArticleFR CMS Multiple Vulnerabilities - Jan15
- Adobe ColdFusion Authentication Bypass Vulnerability
- Acute Control Panel SQL Injection Vulnerability and Remote File Include Vulnerability
- Atlassian JIRA FishEye and Crucible Plugins XML Parsing Unspecified Security Vulnerability