CVE-2014-1923
CVE-2014-1923
Multiple directory traversal vulnerabilities in the (1) staff interface help editor (edithelp.pl) or (2) member-picupload.pl in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, and 3.14.x before 3.14.3 allow remote attackers to write to arbitrary files via unspecified vectors.
Produtos afetados
n/a · n/aQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=11661http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=11662http://koha-community.org/security-release-february-2014/http://www.openwall.com/lists/oss-security/2014/02/07/10http://www.openwall.com/lists/oss-security/2014/02/10/3