CVE-2011-3794: Infoleak
Published Sep 24, 2011
·Updated
Pligg CMS 1.1.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by widgets/statistics/init.php and certain other files.
Affected Software
1 affected component
Pligg Pligg CMS=1.1.3
Event History
Sep 24, 2011
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-3794?
CVE-2011-3794 is considered a low-severity vulnerability that allows exposure of sensitive information.
2
How do I fix CVE-2011-3794?
To fix CVE-2011-3794, upgrade Pligg CMS to a version that does not contain this vulnerability.
3
What information can be exposed by CVE-2011-3794?
CVE-2011-3794 can expose sensitive installation path information through error messages.
4
Which version of Pligg CMS is affected by CVE-2011-3794?
CVE-2011-3794 specifically affects Pligg CMS version 1.1.3.
5
Can CVE-2011-3794 be exploited remotely?
Yes, CVE-2011-3794 can be exploited remotely by attackers through direct requests to certain .php files.