CVE-2011-3699: Infoleak
John Lim ADOdb Library for PHP 5.11 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by tests/test-active-record.php and certain other files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3699?
CVE-2011-3699 is classified as a medium severity vulnerability due to its potential to expose sensitive information.
How do I fix CVE-2011-3699?
To fix CVE-2011-3699, it is recommended to upgrade the ADOdb library to a version later than 5.11.
What type of vulnerability is CVE-2011-3699?
CVE-2011-3699 is an information disclosure vulnerability that allows attackers to access sensitive information via direct requests.
Where can CVE-2011-3699 be exploited?
CVE-2011-3699 can be exploited in any application using the vulnerable version of ADOdb when direct access to certain PHP files is possible.
Who is affected by CVE-2011-3699?
Anyone using ADOdb version 5.11 is affected by CVE-2011-3699 and should take measures to secure their installation.