Lucene search

K
osvGoogleOSV:GHSA-R7P6-FR3X-R877
HistoryMay 17, 2022 - 5:31 a.m.

CakePHP 1.3.7 allows remote attackers to obtain sensitive information via a direct request to a .php file

2022-05-1705:31:33
Google
osv.dev
6
cakephp 1.3.7
remote attackers
sensitive information
direct request
.php file
installation path
error message
security vulnerability

AI Score

6.4

Confidence

Low

EPSS

0.003

Percentile

70.2%

CakePHP 1.3.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by dispatcher.php and certain other files.

AI Score

6.4

Confidence

Low

EPSS

0.003

Percentile

70.2%

Related for OSV:GHSA-R7P6-FR3X-R877