Information Disclosure in OpenDocMan by Open Source Solutions
CVE-2011-3764

Currently unrated

Key Information:

Vendor

Opendocman

Vendor
CVE Published:
24 September 2011

What is CVE-2011-3764?

OpenDocMan 1.2.6-svn-2011-01-21 is susceptible to an information disclosure vulnerability that allows remote attackers to gain sensitive details by directly accessing certain PHP files. This exposure can reveal the installation path and potentially other sensitive information through error messages generated by files like User_Perms_class.php. It's crucial for administrators to mitigate this risk by restricting direct access to such files and implementing appropriate error handling.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.