CVE-2011-2891

Joomla! 1.6.x before 1.6.2 allows remote attackers to obtain sensitive information via an empty Itemid array parameter to index.php, which reveals the installation path in an error message, a different vulnerability than CVE-2011-2488.


We have discovered 268,469 live websites that are affected by CVE-2011-2891.

Test my site




Affected Software

Product  Joomla
Category Content Management System
Vulnerable Domains268,469 live websites (96.66% of Joomla install base)
Vulnerable Versions
  • from 0 before 1.6.2
Vulnerable Versions Count4 versions ( 2.38% of all versions)



Details

  • Published - Jul 28, 2011
  • Updated - Aug 6, 2024

CVE-2011-2891 usage by Country

United States15,557 websites



Italy66,453 websites
Australia24,768 websites
GB16,635 websites
Germany13,780 websites
Russia13,533 websites
Poland12,588 websites
Netherlands11,472 websites
Iran9,178 websites
South Africa8,915 websites

CVE-2011-2891 usage by TLD

.com65,347 websites
.it43,638 websites
.com.au17,014 websites
.ru11,607 websites
.pl8,998 websites
.co.uk8,957 websites
.org7,387 websites
.nl6,817 websites
.de6,532 websites
.net5,785 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2011-2891

Top websites that are affected by CVE-2011-2891. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****************.de Germany*,***
*******.**.ca Canada*,***
**************.********.com United States**,***
***********.com Italy**,***
***********.**.za South Africa**,***
********.com Serbia**,***
***************.com Italy**,***
********.com United States**,***
*********.com GB**,***
*****.**.uk GB**,***
See full domain list

FAQ

A total of 268,469 websites have been identified as vulnerable to CVE-2011-2891, discovered through global website indexing conducted by WebTechSurvey.
Joomla is susceptible to CVE-2011-2891 vulnerability.
Joomla versions before 1.6.2 are vulnerable to CVE-2011-2891.
Version 1.6.2 of Joomla addresses the CVE-2011-2891 security vulnerability.