CVE-2011-3822: Infoleak
Published Sep 24, 2011
·Updated
XOOPS 2.5.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/system/xoopsversion.php and certain other files.
Affected Software
1 affected component
Xoops Xoops=2.5.0
Event History
Sep 24, 2011
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-3822?
CVE-2011-3822 has a medium severity rating as it allows attackers to expose sensitive information.
2
How do I fix CVE-2011-3822?
To fix CVE-2011-3822, you should upgrade to a later version of XOOPS that addresses this vulnerability.
3
What type of information can be leaked by CVE-2011-3822?
CVE-2011-3822 can leak the installation path of the XOOPS system in an error message.
4
Which version of XOOPS is affected by CVE-2011-3822?
CVE-2011-3822 specifically affects XOOPS version 2.5.0.
5
Can exploitation of CVE-2011-3822 lead to further attacks?
Yes, exploitation of CVE-2011-3822 may provide attackers with additional information that could facilitate further attacks.