CVE-2011-2891: Infoleak
Published Jul 27, 2011
·Updated
Joomla! 1.6.x before 1.6.2 allows remote attackers to obtain sensitive information via an empty Itemid array parameter to index.php, which reveals the installation path in an error message, a different vulnerability than CVE-2011-2488.
Affected Software
20 affected components
Joomla Joomla\!=1.6-beta15
Joomla Joomla\!=1.6-beta12
Joomla Joomla\!=1.6-beta3
Joomla Joomla\!=1.6-beta13
Joomla Joomla\!=1.6.1
Joomla Joomla\!=1.6-beta8
Joomla Joomla\!=1.6-beta5
Joomla Joomla\!=1.6.0
Joomla Joomla\!=1.6-beta1
Joomla Joomla\!=1.6-beta6
Joomla Joomla\!=1.6-beta7
Joomla Joomla\!=1.6-beta14
Joomla Joomla\!=1.6-beta11
Joomla Joomla\!=1.6-beta2
Joomla Joomla\!=1.6-alpha2
Joomla Joomla\!=1.6-alpha
Joomla Joomla\!=1.6-beta4
Joomla Joomla\!=1.6-rc1
Joomla Joomla\!=1.6-beta9
Joomla Joomla\!=1.6-beta10
Event History
Jul 27, 2011
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-2891?
CVE-2011-2891 is classified as a medium severity vulnerability due to its ability to disclose installation paths.
2
How do I fix CVE-2011-2891?
To fix CVE-2011-2891, upgrade Joomla! to version 1.6.2 or later.
3
Who is affected by CVE-2011-2891?
CVE-2011-2891 affects Joomla! versions 1.6.x prior to 1.6.2, including various beta versions.
4
What type of vulnerability is CVE-2011-2891?
CVE-2011-2891 is an information disclosure vulnerability.
5
Can CVE-2011-2891 be exploited remotely?
Yes, CVE-2011-2891 can be exploited remotely by sending an empty Itemid array parameter to index.php.