PT-2011-4602 · Cakephp · Cakephp

Published

2011-09-23

·

Updated

2025-01-15

·

CVE-2011-3712

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions CakePHP version 1.3.7
Description The issue allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by dispatcher.php and certain other files.
Recommendations For CakePHP version 1.3.7, consider restricting direct access to .php files, such as dispatcher.php, to prevent the disclosure of sensitive information until a patch is available.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2011-3712
GHSA-R7P6-FR3X-R877

Affected Products

Cakephp