CVE-2011-3755: Infoleak
MantisBT 1.2.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by viewallinc.php and certain other files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3755?
CVE-2011-3755 has been classified as a medium severity vulnerability due to its potential to expose sensitive information.
How do I fix CVE-2011-3755?
To mitigate CVE-2011-3755, it is recommended to upgrade to a later version of MantisBT that does not contain this vulnerability.
What type of vulnerability is CVE-2011-3755?
CVE-2011-3755 is an information disclosure vulnerability that allows attackers to obtain sensitive installation path information.
Which version of MantisBT is affected by CVE-2011-3755?
CVE-2011-3755 specifically affects MantisBT version 1.2.4.
Can CVE-2011-3755 be exploited remotely?
Yes, CVE-2011-3755 can be exploited remotely through direct requests to certain .php files.