CVE-2011-2890

Joomla! < 1.5.23 - Information Disclosure via MediaViewMedia Base Variable

Title source: llm
STIX 2.1

Description

The MediaViewMedia class in administrator/components/com_media/views/media/view.html.php in Joomla! 1.5.23 and earlier allows remote attackers to obtain sensitive information via vectors involving the base variable, leading to disclosure of the installation path, a different vulnerability than CVE-2011-2488.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/68882
Exploit mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2011/07/01/1

Scores

EPSS 0.0027
EPSS Percentile 50.1%

Details

CWE
CWE-200
Status published
Products (24)
joomla/joomla\! 1.5.0
joomla/joomla\! 1.5.1
joomla/joomla\! 1.5.2
joomla/joomla\! 1.5.3
joomla/joomla\! 1.5.4
joomla/joomla\! 1.5.5
joomla/joomla\! 1.5.6
joomla/joomla\! 1.5.7
joomla/joomla\! 1.5.8
joomla/joomla\! 1.5.9
... and 14 more
Published Jul 27, 2011
Tracked Since Feb 18, 2026