{"id":"CVE-2011-3712","aliases":[],"url":"https://o3.security/vulnerability/CVE-2011-3712","summary":"CakePHP 1.3.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by…","details":"CakePHP 1.3.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by dispatcher.php and certain other files.","published":"2011-09-23T23:55:02.427","modified":"2026-06-16T23:33:47.603","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"http://code.google.com/p/inspathx/source/browse/trunk/paths_vuln/%21_README"},{"type":"EXPLOIT","url":"http://code.google.com/p/inspathx/source/browse/trunk/paths_vuln/cakephp-1.3.7"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2011/06/27/6"},{"type":"WEB","url":"http://code.google.com/p/inspathx/source/browse/trunk/paths_vuln/%21_README"},{"type":"EXPLOIT","url":"http://code.google.com/p/inspathx/source/browse/trunk/paths_vuln/cakephp-1.3.7"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2011/06/27/6"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-06-16T23:33:47.603"}}