CVE-2011-3712

EPSS 0.46%

CakePHP 1.3.7 allows remote attackers to obtain sensitive information via a direct request to a .php file

Published: 5/17/2022Modified: 11/8/2023
Also known as:GHSA-r7p6-fr3x-r877

Description

CakePHP 1.3.7 allows remote attackers to obtain sensitive information via a direct request to a `.php` file, which reveals the installation path in an error message, as demonstrated by `dispatcher.php` and certain other files.

Affected packages (1)

References (5)