CVE-2011-3738: Infoleak
Feng Office 1.7.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by public/upgrade/templates/layout.php and certain other files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3738?
CVE-2011-3738 is classified as a moderate severity vulnerability due to the potential exposure of sensitive information.
How do I fix CVE-2011-3738?
To mitigate CVE-2011-3738, you should upgrade to a more recent version of Feng Office that addresses this vulnerability.
What type of information can be exposed by CVE-2011-3738?
CVE-2011-3738 can expose the installation path of the Feng Office application in error messages.
Is CVE-2011-3738 specific to any particular version of Feng Office?
Yes, CVE-2011-3738 specifically affects Feng Office version 1.7.2.
Who is primarily affected by CVE-2011-3738?
Organizations and individuals running Feng Office version 1.7.2 are primarily affected by CVE-2011-3738.