CakePHP 1.3.7 allows remote attackers to obtain sensitive information via a direct request to a .php
file, which reveals the installation path in an error message, as demonstrated by dispatcher.php
and certain other files.
{ "nvd_published_at": "2011-09-23T23:55:00Z", "cwe_ids": [ "CWE-200" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2023-01-14T05:29:43Z" }