CVE-2011-4911: Input Validation
Published Oct 7, 2012
·Updated
Joomla! before 1.5.12 does not perform a JEXEC check in unspecified files, which allows remote attackers to obtain the installation path via unspecified vectors.
Affected Software
12 affected components
Joomla Joomla\!<=1.5.11
Joomla Joomla\!=1.5.3
Joomla Joomla\!=1.5.2
Joomla Joomla\!=1.5.9
Joomla Joomla\!=1.5.4
Joomla Joomla\!=1.5.10
Joomla Joomla\!=1.5.7
Joomla Joomla\!=1.5.0
Joomla Joomla\!=1.5.6
Joomla Joomla\!=1.5.1
Joomla Joomla\!=1.5.8
Joomla Joomla\!=1.5.5
Event History
Oct 7, 2012
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-4911?
CVE-2011-4911 is classified as a medium severity vulnerability due to its potential to expose sensitive information.
2
How do I fix CVE-2011-4911?
To fix CVE-2011-4911, upgrade Joomla! to version 1.5.12 or later, which includes the necessary JEXEC checks.
3
What versions of Joomla! are affected by CVE-2011-4911?
CVE-2011-4911 affects all Joomla! versions prior to 1.5.12, specifically versions 1.5.0 through 1.5.11.
4
What kind of attacks can exploit CVE-2011-4911?
CVE-2011-4911 can be exploited by remote attackers to obtain the installation path of the Joomla! application.
5
Is there a workaround for CVE-2011-4911?
There is no specific workaround for CVE-2011-4911; upgrading to a patched version is the recommended solution.