PT-2011-4602 · Cakephp · Cakephp

CVE-2011-3712

·

Published

2011-09-23

·

Updated

2025-01-15

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions CakePHP version 1.3.7
Description The issue allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by dispatcher.php and certain other files.
Recommendations For CakePHP version 1.3.7, consider restricting direct access to .php files, such as dispatcher.php, to prevent the disclosure of sensitive information until a patch is available.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-3712
GHSA-R7P6-FR3X-R877

Affected Products

Cakephp