CVE-2011-3741: Infoleak
Published Sep 23, 2011
·Updated
Ganglia 3.1.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by hostview.php and certain other files.
Affected Software
1 affected component
Ganglia Ganglia=3.1.7
Event History
Sep 23, 2011
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-3741?
CVE-2011-3741 is classified as a medium severity vulnerability.
2
How do I fix CVE-2011-3741?
To fix CVE-2011-3741, upgrade to a version of Ganglia that is not vulnerable to this issue.
3
What does CVE-2011-3741 affect?
CVE-2011-3741 affects Ganglia version 3.1.7 specifically.
4
What information can be exposed by CVE-2011-3741?
CVE-2011-3741 can expose sensitive information, such as the installation path of Ganglia, through error messages.
5
Can CVE-2011-3741 be exploited remotely?
Yes, CVE-2011-3741 can be exploited by remote attackers via direct requests to certain .php files.