CVE-2011-3717: Infoleak
ClipBucket 2.0.9 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by plugins/signupcaptcha/signupcaptcha.php and certain other files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3717?
CVE-2011-3717 has a medium severity rating as it allows attackers to access sensitive information through direct requests.
How do I fix CVE-2011-3717?
To fix CVE-2011-3717, ensure that your ClipBucket installation is updated to a version that addresses this vulnerability.
What information can be revealed by exploiting CVE-2011-3717?
Exploiting CVE-2011-3717 can reveal the installation path of the ClipBucket application through error messages.
What versions of ClipBucket are affected by CVE-2011-3717?
CVE-2011-3717 affects ClipBucket version 2.0.9.
Is there a way to mitigate the risk associated with CVE-2011-3717?
Mitigating the risk of CVE-2011-3717 involves restricting access to sensitive .php files and upgrading to a secure version.