CVE-2011-3791: Infoleak
Published Sep 24, 2011
·Updated
Piwik 1.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by plugins/Widgetize/Widgetize.php and certain other files.
Affected Software
1 affected component
Matomo Matomo=1.1
Event History
Sep 24, 2011
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-3791?
CVE-2011-3791 is considered a moderate severity vulnerability because it allows remote attackers to gain information about the system's installation path.
2
How do I fix CVE-2011-3791?
To fix CVE-2011-3791, upgrade to a later version of Piwik or restrict access to sensitive PHP files.
3
What type of vulnerability is CVE-2011-3791?
CVE-2011-3791 is an information disclosure vulnerability that allows exposure of sensitive server paths.
4
What are the potential impacts of CVE-2011-3791?
The potential impacts of CVE-2011-3791 include increased risk of targeted attacks due to exposed server file paths.
5
Which version of Matomo is affected by CVE-2011-3791?
CVE-2011-3791 affects Matomo version 1.1.