First published: Fri Sep 23 2011(Updated: )
John Lim ADOdb Library for PHP 5.11 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by tests/test-active-record.php and certain other files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
John Lim ADOdb Date Library | =5.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-3699 is classified as a medium severity vulnerability due to its potential to expose sensitive information.
To fix CVE-2011-3699, it is recommended to upgrade the ADOdb library to a version later than 5.11.
CVE-2011-3699 is an information disclosure vulnerability that allows attackers to access sensitive information via direct requests.
CVE-2011-3699 can be exploited in any application using the vulnerable version of ADOdb when direct access to certain PHP files is possible.
Anyone using ADOdb version 5.11 is affected by CVE-2011-3699 and should take measures to secure their installation.