CVE-2011-3712
Publication date 23 September 2011
Last updated 24 July 2024
Ubuntu priority
Description
CakePHP 1.3.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by dispatcher.php and certain other files.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| cakephp | 18.04 LTS bionic | Not in release |
| 16.04 LTS xenial |
Not affected
|
|
| 14.04 LTS trusty | Not in release | |