CVE-2011-3825 — Sensitive Information Exposure in Framework
Severity
5.0MEDIUMNVD
EPSS
0.3%
top 48.75%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 24
Latest updateMay 17
Description
Zend Framework 1.11.3 in Zend Server CE 5.1.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by Validate.php and certain other files.
CVSS vector
AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9
Affected Packages2 packages
🔴Vulnerability Details
2💬Community
3Bugzilla▶
CVE-2011-3825 php-ZendFramework: Installation path disclosure via a direct request to a Validate.php file↗2011-09-26
Bugzilla▶
CVE-2011-3825 php-ZendFramework: Installation path disclosure via a direct request to a Validate.php file [epel-6]↗2011-09-26
Bugzilla▶
CVE-2011-3825 php-ZendFramework: Installation path disclosure via a direct request to a Validate.php file [fedora-all]↗2011-09-26