CVE-2011-3806: Infoleak
TCExam 11.1.015 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by public/code/tcepagefooter.php and certain other files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3806?
CVE-2011-3806 is considered a medium severity vulnerability due to its potential to expose sensitive information.
How do I fix CVE-2011-3806?
To fix CVE-2011-3806, ensure that sensitive PHP files are not directly accessible and implement proper access controls.
What impact does CVE-2011-3806 have on TCExam 11.1.015?
CVE-2011-3806 allows remote attackers to access sensitive information, potentially leading to the disclosure of the installation path.
Is CVE-2011-3806 exploitable remotely?
Yes, CVE-2011-3806 is exploitable remotely as it allows attackers to make direct requests to vulnerable PHP files.
What PHP files are known to be affected by CVE-2011-3806?
CVE-2011-3806 has been demonstrated in files such as public/code/tce_page_footer.php, among others.