First published: Fri Sep 23 2011(Updated: )
ClanTiger 1.1.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by widgets/statistics/statistics.php and certain other files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tiger Tiger | =1.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-3715 is considered a medium severity vulnerability due to its potential for exposing sensitive installation path information.
To fix CVE-2011-3715, ensure that direct access to sensitive .php files is restricted and implement access controls on the server.
CVE-2011-3715 affects ClanTiger version 1.1.3.
CVE-2011-3715 facilitates information disclosure attacks by revealing sensitive installation paths to remote attackers.
Mitigation for CVE-2011-3715 includes restricting access to vulnerable files and regularly updating your software to address known vulnerabilities.