Vulnerability index

Browse CVEs

7,769 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Cakephp MEDIUM 5.0
CVE-2011-3712

CakePHP 1.3.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an …

No fix yet
Fix from $1,600 2011-09-23
Cftp MEDIUM 5.0
CVE-2011-3713EPSS 7%

cFTP r80 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error…

No fix yet
Fix from $1,600 2011-09-23
Clansphere MEDIUM 5.0
CVE-2011-3714

ClanSphere 2010.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in…

No fix yet
Fix from $1,600 2011-09-23
Clantiger MEDIUM 5.0
CVE-2011-3715

ClanTiger 1.1.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in a…

No fix yet
Fix from $1,600 2011-09-23
Claroline MEDIUM 5.0
CVE-2011-3716

Claroline 1.9.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in a…

No fix yet
Fix from $1,600 2011-09-23
Clipbucket MEDIUM 5.0
CVE-2011-3717

ClipBucket 2.0.9 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in …

No fix yet
Fix from $1,600 2011-09-23
Cms Made Simple MEDIUM 5.0
CVE-2011-3718

CMS Made Simple (CMSMS) 1.9.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installa…

No fix yet
Fix from $1,600 2011-09-23
Codeigniter MEDIUM 5.0
CVE-2011-3719

CodeIgniter 1.7.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in…

No fix yet
Fix from $1,600 2011-09-23
Conceptcms MEDIUM 5.0
CVE-2011-3720

conceptcms 5.3.1, 5.3.3, and possibly other versions allows remote attackers to obtain sensitive information via a direct request to a .php file, whi…

No fix yet
Fix from $1,600 2011-09-23
Concrete MEDIUM 5.0
CVE-2011-3721

concrete 5.4.0.5, 5.4.1, and 5.4.1.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the i…

No fix yet
Fix from $1,600 2011-09-23
Coppermine Photo Gallery MEDIUM 5.0
CVE-2011-3722

Coppermine Photo Gallery (CPG) 1.5.12 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the …

No fix yet
Fix from $1,600 2011-09-23
Crafty Syntax MEDIUM 5.0
CVE-2011-3723

Crafty Syntax 3.0.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path …

No fix yet
Fix from $1,600 2011-09-23
Cubecart MEDIUM 5.0
CVE-2011-3724

CubeCart 4.4.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an…

No fix yet
Fix from $1,600 2011-09-23
Deluxebb MEDIUM 5.0
CVE-2011-3725

DeluxeBB 1.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an e…

No fix yet
Fix from $1,600 2011-09-23
111webcalendar MEDIUM 5.0
CVE-2011-3695

111WebCalendar 1.2.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path…

No fix yet
Fix from $1,600 2011-09-23
60cyclecms MEDIUM 5.0
CVE-2011-3696

60cycleCMS 2.5.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in …

No fix yet
Fix from $1,600 2011-09-23
Achievo MEDIUM 5.0
CVE-2011-3697

Achievo 1.4.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an …

No fix yet
Fix from $1,600 2011-09-23
Adaptcms MEDIUM 5.0
CVE-2011-3698

AdaptCMS 2.0.2 Beta allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path …

No fix yet
Fix from $1,600 2011-09-23
Adodb MEDIUM 5.0
CVE-2011-3699

John Lim ADOdb Library for PHP 5.11 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the in…

No fix yet
Fix from $1,600 2011-09-23
Advanced Electron Forum MEDIUM 5.0
CVE-2011-3700

Advanced Electron Forum (AEF) 1.0.8 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the in…

No fix yet
Fix from $1,600 2011-09-23
Alegrocart MEDIUM 5.0
CVE-2011-3701

AlegroCart 1.2.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in …

No fix yet
Fix from $1,600 2011-09-23
Ananta Gazelle MEDIUM 5.0
CVE-2011-3702

Ananta Gazelle 1.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path i…

No fix yet
Fix from $1,600 2011-09-23
Scadapro HIGH 10.0
CVE-2011-3497EPSS 57%

service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary DLL functions via the XF function, possibly relate…

Fix: after 4.0.0
Fix from $1,950 2011-09-16
Cogent Datahub MEDIUM 5.0
CVE-2011-3502EPSS 6%

The web server in Cogent DataHub 7.1.1.63 and earlier allows remote attackers to obtain the source code of executable files via a request with a trai…

No fix yet
Fix from $1,600 2011-09-16
Bi Server MEDIUM 5.0
CVE-2009-5101

Pentaho BI Server 1.7.0.1062 and earlier includes the session ID (JSESSIONID) in the URL, which allows attackers to obtain it from session history, r…

Fix: after 1.7.0.1062
Fix from $1,600 2011-09-13
Unified Communications Manager HIGH 10.0
CVE-2011-1643

Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x, 7.x before 7.1(5b)su4, 8.0, and 8.5 before 8.5(1)su2 and Cisco Unified Pre…

Mitigation only
Fix from $1,950 2011-08-29
Envision MEDIUM 5.0
CVE-2011-2737

RSA enVision 3.x and 4.x before 4 SP4 P3 allows remote attackers to read arbitrary files via unspecified vectors, related to an "arbitrary file retri…

Fix: after 4.0
Fix from $1,600 2011-08-25
Zabbix MEDIUM 5.0
CVE-2011-3264

Zabbix before 1.8.6 allows remote attackers to obtain sensitive information via an invalid srcfld2 parameter to popup.php, which reveals the installa…

Fix: after 1.8.5
Fix from $1,600 2011-08-19
Zabbix MEDIUM 5.0
CVE-2011-3265

popup.php in Zabbix before 1.8.7 allows remote attackers to read the contents of arbitrary database tables via a modified srctbl parameter.

Fix: after 1.8.6
Fix from $1,600 2011-08-19
Firefox MEDIUM 5.0
CVE-2011-2986

Mozilla Firefox 4.x through 5, Thunderbird before 6, SeaMonkey 2.x before 2.3, and possibly other products, when the Direct2D (aka D2D) API is used o…

Fix: after 5.0
Fix from $1,600 2011-08-18