{"id":"CVE-2011-3712","aliases":[],"url":"https://o3.security/vulnerability/CVE-2011-3712","summary":"CakePHP 1.3.7 allows remote attackers to obtain sensitive information via a direct request to a .php file","details":"CakePHP 1.3.7 allows remote attackers to obtain sensitive information via a direct request to a `.php` file, which reveals the installation path in an error message, as demonstrated by `dispatcher.php` and certain other files.","published":"2022-05-17T05:31:33Z","modified":"2023-11-08T03:57:00.951504Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"cakephp/cakephp","fixedVersion":"1.3.8"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2011-3712"},{"type":"PACKAGE","url":"https://github.com/cakephp/cakephp"},{"type":"WEB","url":"http://code.google.com/p/inspathx/source/browse/trunk/paths_vuln/%21_README"},{"type":"WEB","url":"http://code.google.com/p/inspathx/source/browse/trunk/paths_vuln/cakephp-1.3.7"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2011/06/27/6"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T03:57:00.951504Z"}}