Total
9656 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2011-3818 | 1 Wordpress | 1 Wordpress | 2025-04-11 | N/A |
WordPress 2.9.2 and 3.0.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by wp-admin/includes/user.php and certain other files. | ||||
CVE-2011-3816 | 1 Webinsta | 1 Mailing List Manager | 2025-04-11 | N/A |
WEBinsta mailing list manager 1.3e allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by install/install3.php and certain other files. | ||||
CVE-2013-0786 | 1 Mozilla | 1 Bugzilla | 2025-04-11 | N/A |
The Bugzilla::Search::build_subselect function in Bugzilla 2.x and 3.x before 3.6.13 and 3.7.x and 4.0.x before 4.0.10 generates different error messages for invalid product queries depending on whether a product exists, which allows remote attackers to discover private product names by using debug mode for a query. | ||||
CVE-2011-3812 | 1 Vanillaforums | 1 Vanilla | 2025-04-11 | N/A |
Vanilla 2.0.16 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by plugins/Minify/min/utils.php and certain other files. | ||||
CVE-2011-3799 | 1 Elazos | 1 Reos | 2025-04-11 | N/A |
ReOS 2.0.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by padmin/blocks/vergal.php and certain other files. | ||||
CVE-2011-3797 | 1 Projectpier | 1 Projectpier | 2025-04-11 | N/A |
ProjectPier 0.8.0.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by public/upgrade/templates/layout.php and certain other files. | ||||
CVE-2011-3792 | 1 Pixelpost | 1 Pixelpost | 2025-04-11 | N/A |
Pixelpost 1.7.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by includes/functions_feeds.php and certain other files. | ||||
CVE-2011-3786 | 1 Phprojekt | 1 Phprojekt | 2025-04-11 | N/A |
PHProjekt 6.0.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by Setup/Controllers/IndexController.php. | ||||
CVE-2011-3775 | 1 Litoweb | 1 Phpfilenavigator | 2025-04-11 | N/A |
PHPfileNavigator 2.3.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by xestion/varios/logs.inc.php and certain other files. | ||||
CVE-2013-0599 | 1 Ibm | 1 Rational Directory Server | 2025-04-11 | N/A |
IBM Eclipse Help System (IEHS), as used in IBM Rational Directory Server 5.1.1 through 5.1.1.2 and 5.2 through 5.2.1 and other products, allows remote attackers to obtain sensitive information by providing a crafted parameter path and then reading the debug information associated with the 500 HTTP status code. | ||||
CVE-2011-3771 | 1 Gnu | 1 Phpbook | 2025-04-11 | N/A |
phpBook 2.1.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by doc/update_smilies_1.50-1.60.php and certain other files. | ||||
CVE-2011-3763 | 1 Opencart | 1 Opencart | 2025-04-11 | N/A |
OpenCart 1.4.9.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by system/startup.php and certain other files. | ||||
CVE-2011-3761 | 1 Dietrich Ayala | 1 Nusoap | 2025-04-11 | N/A |
NuSOAP 0.9.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by nuSOAP/classes/class.wsdl.php and certain other files. | ||||
CVE-2011-3759 | 1 Mybb | 1 Mybb | 2025-04-11 | N/A |
MyBB (aka MyBulletinBoard) 1.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by inc/3rdparty/diff/Diff/ThreeWay.php and certain other files. | ||||
CVE-2011-3757 | 1 Moodle | 1 Moodle | 2025-04-11 | N/A |
Moodle 2.0.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by webservice/xmlrpc/locallib.php and certain other files. | ||||
CVE-2011-3756 | 1 Microblog | 1 Microblog | 2025-04-11 | N/A |
MicroBlog 0.9.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by init.php and certain other files. | ||||
CVE-2011-3753 | 1 Linpha | 1 Linpha | 2025-04-11 | N/A |
LinPHA 1.3.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by viewer.php and certain other files. | ||||
CVE-2011-3750 | 1 Kplaylist | 1 Kplaylist | 2025-04-11 | N/A |
kPlaylist 1.8.502 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by getid3/getid3/write.id3v1.php and certain other files. | ||||
CVE-2011-3749 | 1 Maptools | 1 Ka-map | 2025-04-11 | N/A |
ka-Map 1.0-20070205 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by test.php and certain other files. | ||||
CVE-2011-2774 | 1 Mahara | 1 Mahara | 2025-04-11 | N/A |
The "Reply to message" feature in Mahara 1.3.x and 1.4.x before 1.4.1 allows remote authenticated users to read the messages of a different user via a modified replyto parameter. |