Vulnerability Description
The (1) templatewrap/templatefoot.php, (2) cmsjs/plugin.js.php, and (3) cmsincludes/cms_plugin_api_link.inc.php scripts in Tribal Tribiq CMS before 5.2.7c allow remote attackers to obtain sensitive information via a direct request, which reveals the full path in an error message.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tribiq | Tribiq Cms | <= 5.2.7b |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2011-2727?
CVE-2011-2727 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The (1) templatewrap/templatefoot.php, (2) cmsjs/plugin.js.php, and (3) cmsincludes/cms_plugin_api_link.inc.php scripts in Tribal Tribiq CMS before 5.2.7c allow remote attackers to obtain sensitive in...
How severe is CVE-2011-2727?
CVE-2011-2727 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2011-2727?
Check the references section above for vendor advisories and patch information. Affected products include: Tribiq Tribiq Cms.