MEDIUM5.3
GHSA-jw86-5cjf-mv79
HTML Purifier allows remote attackers to obtain sensitive information
Details
HTML Purifier 4.2.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by tests/PHPT/Reporter/SimpleTest.php and certain other files.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/ezyang/htmlpurifier
Introduced in:
0No fixed version published yet for ezyang/htmlpurifier (composer). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2011-3744[ADVISORY]
- https://github.com/ezyang/htmlpurifier[PACKAGE]
- http://code.google.com/p/inspathx/source/browse/trunk/paths_vuln/%21_README[WEB]
- http://code.google.com/p/inspathx/source/browse/trunk/paths_vuln/htmlpurifier-4.2.0[WEB]
- http://www.openwall.com/lists/oss-security/2011/06/27/6[WEB]