CVE-2011-3744: Infoleak
HTML Purifier 4.2.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by tests/PHPT/Reporter/SimpleTest.php and certain other files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3744?
CVE-2011-3744 has a medium severity rating as it allows remote attackers to disclose sensitive information.
How do I fix CVE-2011-3744?
To fix CVE-2011-3744, upgrade to a later version of HTML Purifier that is not affected by this vulnerability.
What kinds of attacks does CVE-2011-3744 facilitate?
CVE-2011-3744 facilitates information disclosure attacks by revealing installation paths in error messages.
Which version of HTML Purifier is affected by CVE-2011-3744?
CVE-2011-3744 affects HTML Purifier version 4.2.0.
What can attackers gain from exploiting CVE-2011-3744?
Attackers exploiting CVE-2011-3744 can gain insights into the internal structure of the application, potentially aiding in further attacks.