5
CVSSv2

CVE-2011-3825

Published: 24/09/2011 Updated: 21/05/2012
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Zend Framework 1.11.3 in Zend Server CE 5.1.0 allows remote malicious users to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by Validate.php and certain other files.

Vulnerable Product Search on Vulmon Subscribe to Product

zend framework 1.11.3

zend server 5.1.0