First published: Fri Sep 23 2011(Updated: )
b2evolution 3.3.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by locales/ru_RU/ru-RU.locale.php and certain other files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Evolution | =3.3.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-3709 has a moderate severity rating due to potential information disclosure.
To fix CVE-2011-3709, restrict direct access to sensitive .php files or apply the latest security updates for b2evolution.
Attackers can gain sensitive information including the installation path of the b2evolution application due to error messages.
CVE-2011-3709 affects b2evolution version 3.3.3.
Yes, CVE-2011-3709 remains relevant for those using the vulnerable version of b2evolution without patches.