CVE-2011-2891

Joomla! 1.6.x before 1.6.2 allows remote attackers to obtain sensitive information via an empty Itemid array parameter to index.php, which reveals the installation path in an error message, a different vulnerability than CVE-2011-2488.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 29%
VendorProductVersion
joomlajoomla\!
1.6:alpha
joomlajoomla\!
1.6:alpha2
joomlajoomla\!
1.6:beta1
joomlajoomla\!
1.6:beta10
joomlajoomla\!
1.6:beta11
joomlajoomla\!
1.6:beta12
joomlajoomla\!
1.6:beta13
joomlajoomla\!
1.6:beta14
joomlajoomla\!
1.6:beta15
joomlajoomla\!
1.6:beta2
joomlajoomla\!
1.6:beta3
joomlajoomla\!
1.6:beta4
joomlajoomla\!
1.6:beta5
joomlajoomla\!
1.6:beta6
joomlajoomla\!
1.6:beta7
joomlajoomla\!
1.6:beta8
joomlajoomla\!
1.6:beta9
joomlajoomla\!
1.6:rc1
joomlajoomla\!
1.6.0
joomlajoomla\!
1.6.1
𝑥
= Vulnerable software versions