{"id":"UBUNTU-CVE-2011-3712","details":"CakePHP 1.3.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by dispatcher.php and certain other files.","modified":"2025-07-16T07:30:49.729434Z","published":"2011-09-23T23:55:00Z","withdrawn":"2025-07-18T16:42:44Z","upstream":["CVE-2011-3712"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2011-3712"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2011-3712"}],"affected":[{"package":{"name":"cakephp","ecosystem":"Ubuntu:14.04:LTS","purl":"pkg:deb/ubuntu/cakephp@1.3.15-1+deb7u2build0.14.04.1?arch=source&distro=trusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.15-1+deb7u2build0.14.04.1"}]}],"versions":["1.3.15-1"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"cakephp","binary_version":"1.3.15-1+deb7u2build0.14.04.1"},{"binary_name":"cakephp-scripts","binary_version":"1.3.15-1+deb7u2build0.14.04.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2011/UBUNTU-CVE-2011-3712.json"}},{"package":{"name":"cakephp","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/cakephp@2.8.0-1?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.8.0-1"}]}],"versions":["2.7.2-1"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"cakephp","binary_version":"2.8.0-1"},{"binary_name":"cakephp-scripts","binary_version":"2.8.0-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2011/UBUNTU-CVE-2011-3712.json"}}],"schema_version":"1.7.3","severity":[{"type":"Ubuntu","score":"low"}]}