PT-2011-4602 · Cakephp · Cakephp

CVE-2011-3712

·

Publicado

2011-09-23

·

Atualizado

2025-01-15

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions CakePHP version 1.3.7
Description The issue allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by dispatcher.php and certain other files.
Recommendations For CakePHP version 1.3.7, consider restricting direct access to .php files, such as dispatcher.php, to prevent the disclosure of sensitive information until a patch is available.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-3712
GHSA-R7P6-FR3X-R877

Produtos afetados

Cakephp