First published: Fri Sep 23 2011(Updated: )
HTML Purifier 4.2.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by tests/PHPT/Reporter/SimpleTest.php and certain other files.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/ezyang/htmlpurifier | <=4.2.0 | |
HTML Purifier | =4.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-3744 has a medium severity rating as it allows remote attackers to disclose sensitive information.
To fix CVE-2011-3744, upgrade to a later version of HTML Purifier that is not affected by this vulnerability.
CVE-2011-3744 facilitates information disclosure attacks by revealing installation paths in error messages.
CVE-2011-3744 affects HTML Purifier version 4.2.0.
Attackers exploiting CVE-2011-3744 can gain insights into the internal structure of the application, potentially aiding in further attacks.