CVE-2011-3790: Infoleak
Piwigo 2.1.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by tools/metadata.php and certain other files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3790?
CVE-2011-3790 is considered a moderate severity vulnerability as it allows remote attackers to gain sensitive information.
How do I fix CVE-2011-3790?
To fix CVE-2011-3790, you should upgrade to a later version of Piwigo that does not expose sensitive information through error messages.
What are the potential impacts of CVE-2011-3790?
The potential impacts of CVE-2011-3790 include unauthorized access to installation paths that could aid attackers in further exploits.
Which versions of Piwigo are affected by CVE-2011-3790?
CVE-2011-3790 specifically affects Piwigo version 2.1.5.
Are there any known exploits for CVE-2011-3790?
Yes, CVE-2011-3790 can be exploited through direct requests to certain PHP files, leading to disclosure of sensitive information.