CVE-2011-3710: Infoleak
Published Sep 23, 2011
·Updated
bbPress 1.0.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by bb-templates/kakumei/view.php and certain other files.
Affected Software
1 affected component
bbPress bbPress=1.0.2
Event History
Sep 23, 2011
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-3710?
CVE-2011-3710 has a medium severity rating as it allows attackers to disclose sensitive information.
2
How do I fix CVE-2011-3710?
To fix CVE-2011-3710, upgrade to a newer, patched version of bbPress that addresses this vulnerability.
3
What does CVE-2011-3710 exploit?
CVE-2011-3710 exploits the ability to directly access specific .php files in bbPress to reveal installation paths in error messages.
4
Which version of bbPress is affected by CVE-2011-3710?
bbPress version 1.0.2 is specifically affected by CVE-2011-3710.
5
Who is affected by CVE-2011-3710?
Any users running bbPress 1.0.2 are at risk from CVE-2011-3710 if they have not applied a security update.