CVE-2011-3712

EPSS 0.46%

CakePHP 1.3.7 allows remote attackers to obtain sensitive information via a direct request to a .php file

發布日:2022/5/17修改日:2023/11/8

描述

CakePHP 1.3.7 allows remote attackers to obtain sensitive information via a direct request to a `.php` file, which reveals the installation path in an error message, as demonstrated by `dispatcher.php` and certain other files.

受影響套件(1)

參考連結(5)