CVE-2011-3699

Severity
5.0MEDIUM
EPSS
0.3%
top 48.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 23
Latest updateMay 17

Description

John Lim ADOdb Library for PHP 5.11 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by tests/test-active-record.php and certain other files.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

NVDjohn_lim/adodb5.11

🔴Vulnerability Details

3
GHSA
GHSA-r7mm-g549-9cj6: John Lim ADOdb Library for PHP 52022-05-17
CVEList
CVE-2011-3699: John Lim ADOdb Library for PHP 52011-09-23
OSV
CVE-2011-3699: John Lim ADOdb Library for PHP 52011-09-23

📋Vendor Advisories

1
Debian
CVE-2011-3699: libphp-adodb - John Lim ADOdb Library for PHP 5.11 allows remote attackers to obtain sensitive ...2011

💬Community

3
Bugzilla
CVE-2011-3699 php-adodb: installation path disclosure via a direct request to a .php file [fedora-all]2011-09-26
Bugzilla
CVE-2011-3699 php-adodb: installation path disclosure via a direct request to a .php file2011-09-26
Bugzilla
CVE-2011-3699 php-adodb: installation path disclosure via a direct request to a .php file [epel-all]2011-09-26
CVE-2011-3699 (MEDIUM CVSS 5) | John Lim ADOdb Library for PHP 5.11 | cvebase.io