Vulnerability index

Browse CVEs

7,769 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Webmail MEDIUM 5.0
CVE-2005-4368

roundcube webmail Alpha, with a default high verbose level ($rcmail_config['debug_level'] = 1), allows remote attackers to obtain the full path of th…

Mitigation only
Fix from $1,600 2005-12-20
Limbo Cms MEDIUM 5.0
CVE-2005-4320

Limbo CMS 1.0.4.2 and earlier allows remote attackers to obtain the installation path of the application via a direct request to (1) doc.inc.php, (2)…

Fix: after 1.0.4.2
Fix from $1,600 2005-12-17
Phpcoin MEDIUM 5.0
CVE-2005-4214

phpCOIN 1.2.2 allows remote attackers to obtain the installation path via a direct request to config.php, which leaks the path in an error message be…

No fix yet
Fix from $1,600 2005-12-14
Jetty MEDIUM 5.0
CVE-2005-3747

Unspecified vulnerability in Jetty before 5.1.6 allows remote attackers to obtain source code of JSP pages, possibly involving requests for .jsp file…

Fix: after 5.1.5
Fix from $1,600 2005-11-22
P2000w Version 1 Voip Wifi Phone MEDIUM 6.4
CVE-2005-3724

Zyxel P2000W Version 1 VOIP WIFI Phone Wj.00.10 allows remote attackers to obtain sensitive information and possibly cause a denial of service via a …

Mitigation only
Fix from $1,600 2005-11-21
Tikiwiki Cms\/groupware MEDIUM 5.0
CVE-2005-3529

tiki-view_forum_thread.php in TikiWiki 1.9.0 through 1.9.2 allows remote attackers to obtain the installation path via an invalid topics_sort_mode pa…

No fix yet
Fix from $1,600 2005-11-20
Phpadsnew MEDIUM 5.0
CVE-2005-3645

phpAdsNew and phpPgAds 2.0.6 and possibly earlier versions allows remote attackers to obtain the application installation path and other sensitive in…

Patch available
Fix from $1,600 2005-11-17
Cool Cafe Chat HIGH 7.5
CVE-2005-2036

modifyUser.asp in Cool Cafe (Cool Café) Chat 1.2.1 allows remote attackers to obtain the administrator password and email address via a modified nick…

No fix yet
Fix from $1,950 2005-06-16
Php Nuke MEDIUM 5.0
CVE-2005-1028

PHP-Nuke 6.x through 7.6 allows remote attackers to obtain sensitive information via a direct request to (1) index.php with the forum_admin parameter…

Fix: after 7.6
Fix from $1,600 2005-05-02
Unclassified MEDIUM 5.0
CVE-2005-0797

Novell iChain Mini FTP Server 2.3 displays different error messages if a user exists or not, which allows remote attackers to obtain sensitive inform…

Mitigation only
Fix from $1,600 2005-03-15
Weblogic Server MEDIUM 5.3
CVE-2004-2320

The default configuration of BEA WebLogic Server and Express 8.1 SP2 and earlier, 7.0 SP4 and earlier, 6.1 through SP6, and 5.1 through SP13 responds…

Patch available
Fix from $1,600 2004-12-31
Tikiwiki Cms\/groupware MEDIUM 5.0
CVE-2004-1923

Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to gain sensitive information via a direct request to (1) banner_click.php, (…

Fix: after 1.8.1
Fix from $1,600 2004-04-11
Exchange Server MEDIUM 6.0
CVE-2003-0904EPSS 8%

Microsoft Exchange 2003 and Outlook Web Access (OWA), when configured to use NTLM authentication, does not properly reuse HTTP connections, which can…

Patch available
Fix from $1,600 2004-01-20
Clarkconnect MEDIUM 5.0
CVE-2003-1379

clarkconnectd in ClarkConnect Linux 1.2 allows remote attackers to obtain sensitive information about the server via the characters (1) A, which reve…

Patch available
Fix from $1,600 2003-12-31
iOS HIGH 9.3
CVE-2003-1398

Cisco IOS 12.0 through 12.2, when IP routing is disabled, accepts false ICMP redirect messages, which allows remote attackers to cause a denial of se…

Mitigation only
Fix from $1,950 2003-12-31
Botbr HIGH 7.5
CVE-2003-1404

DotBr 0.1 stores config.inc with insufficient access control under the web document root, which allows remote attackers to obtain sensitive informati…

Mitigation only
Fix from $1,950 2003-12-31
Domino Server MEDIUM 5.0
CVE-2003-1408

Lotus Domino Server 5.0 and 6.0 allows remote attackers to read the source code for files via an HTTP request with a filename with a trailing dot.

No fix yet
Fix from $1,600 2003-12-31
Topo MEDIUM 5.0
CVE-2003-1409

TOPo 1.43 allows remote attackers to obtain sensitive information by sending an HTTP request with an invalid parameter to (1) in.php or (2) out.php, …

Patch available
Fix from $1,600 2003-12-31
Coldfusion MEDIUM 5.0
CVE-2003-1469EPSS 6%

The default configuration of ColdFusion MX has the "Enable Robust Exception Information" option selected, which allows remote attackers to obtain the…

No fix yet
Fix from $1,600 2003-12-31
Communigate Pro MEDIUM 5.8
CVE-2003-1481

CommuniGate Pro 3.1 through 4.0.6 sends the session ID in the referer field for an HTTP request for an image, which allows remote attackers to hijack…

Patch available
Fix from $1,600 2003-12-31
Phorum MEDIUM 5.0
CVE-2003-1486

Phorum 3.4 through 3.4.2 allows remote attackers to obtain the full path of the web server via an incorrect HTTP request to (1) smileys.php, (2) quic…

Patch available
Fix from $1,600 2003-12-31
Shopping Cart MEDIUM 5.0
CVE-2003-1517

cart.pl in Dansie shopping cart allows remote attackers to obtain the installation path via an invalid db parameter, which leaks the path in an error…

No fix yet
Fix from $1,600 2003-12-31
Php Nuke MEDIUM 5.0
CVE-2003-1526

PHP-Nuke 7.0 allows remote attackers to obtain the installation path via certain characters such as (1) ", (2) ', or (3) > in the search field, which…

No fix yet
Fix from $1,600 2003-12-31
Guestbook MEDIUM 5.0
CVE-2003-1535

Justice Guestbook 1.3 allows remote attackers to obtain the full installation path via a direct request to cfooter.php3, which leaks the path in an e…

No fix yet
Fix from $1,600 2003-12-31
Wfchat MEDIUM 5.0
CVE-2003-1540

WF-Chat 1.0 Beta stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain authentica…

Mitigation only
Fix from $1,600 2003-12-31
Myabracadaweb MEDIUM 5.0
CVE-2003-1548EPSS 7%

MyABraCaDaWeb 1.0.2 and earlier allows remote attackers to obtain sensitive information via an invalid IDAdmin or other parameter, which reveals the …

Fix: after 1.0.2
Fix from $1,600 2003-12-31
Xoops MEDIUM 5.0
CVE-2003-1550

XOOPS 2.0, and possibly earlier versions, allows remote attackers to obtain sensitive information via an invalid xoopsOption parameter, which reveals…

Fix: after 2.0
Fix from $1,600 2003-12-31
Scozbook MEDIUM 5.0
CVE-2003-1555

ScozNet ScozBook 1.1 BETA allows remote attackers to obtain sensitive information via an invalid PG parameter in view.php, which reveals the installa…

No fix yet
Fix from $1,600 2003-12-31
Ie MEDIUM 5.0
CVE-2003-1559EPSS 16%

Microsoft Internet Explorer 5.22, and other 5 through 6 SP1 versions, sends Referer headers containing https:// URLs in requests for http:// URLs, wh…

Mitigation only
Fix from $1,600 2003-12-31
Navigator MEDIUM 5.0
CVE-2003-1560

Netscape 4 sends Referer headers containing https:// URLs in requests for http:// URLs, which allows remote attackers to obtain potentially sensitive…

Mitigation only
Fix from $1,600 2003-12-31