CVE-2011-3825Sensitive Information Exposure in Framework

Severity
5.0MEDIUMNVD
EPSS
0.3%
top 48.75%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 24
Latest updateMay 17

Description

Zend Framework 1.11.3 in Zend Server CE 5.1.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by Validate.php and certain other files.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

NVDzend/server5.1.0
NVDzend/framework1.11.3

🔴Vulnerability Details

2
GHSA
GHSA-fhjm-rh64-w3x4: Zend Framework 12022-05-17
OSV
CVE-2011-3825: Zend Framework 12011-09-24

💬Community

3
Bugzilla
CVE-2011-3825 php-ZendFramework: Installation path disclosure via a direct request to a Validate.php file2011-09-26
Bugzilla
CVE-2011-3825 php-ZendFramework: Installation path disclosure via a direct request to a Validate.php file [epel-6]2011-09-26
Bugzilla
CVE-2011-3825 php-ZendFramework: Installation path disclosure via a direct request to a Validate.php file [fedora-all]2011-09-26
CVE-2011-3825 — Sensitive Information Exposure | cvebase