CVE-2011-2889: Infoleak
templates/system/error.php in Joomla! before 1.5.23 might allow remote attackers to obtain sensitive information via unspecified vectors that trigger an undefined value of a certain error field, leading to disclosure of the installation path. NOTE: this might overlap CVE-2011-2488.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2889?
CVE-2011-2889 is classified with a medium severity due to its potential to disclose sensitive information.
How do I fix CVE-2011-2889?
To fix CVE-2011-2889, upgrade Joomla! to version 1.5.23 or later.
What versions of Joomla! are affected by CVE-2011-2889?
CVE-2011-2889 affects Joomla! versions prior to 1.5.23, including 1.5.0 to 1.5.22.
What type of vulnerability is CVE-2011-2889?
CVE-2011-2889 is an information disclosure vulnerability that may allow remote attackers to expose sensitive information.
Can CVE-2011-2889 be exploited remotely?
Yes, CVE-2011-2889 can be exploited remotely by attackers to obtain the installation path of the Joomla! application.