VYPR

CVEs

346,414 total · page 5982 of 6,929

  • CVE-2011-3746Sep 23, 2011
    risk 0.00cvss epss 0.01

    Jcow 4.2.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by themes/default/page.tpl.php and certain other files.

  • CVE-2011-3745Sep 23, 2011
    risk 0.00cvss epss 0.01

    HycusCMS 1.0.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by templates/hycus_template/template.php.

  • CVE-2011-3744Sep 23, 2011
    risk 0.00cvss epss 0.01

    HTML Purifier 4.2.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by tests/PHPT/Reporter/SimpleTest.php and certain other files.

  • CVE-2011-3743Sep 23, 2011
    risk 0.00cvss epss 0.01

    Hesk 2.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by inc/footer.inc.php and certain other files.

  • CVE-2011-3742Sep 23, 2011
    risk 0.00cvss epss 0.01

    HelpCenter Live 2.1.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/HelpCenter/index.php and certain other files.

  • CVE-2011-3741Sep 23, 2011
    risk 0.00cvss epss 0.01

    Ganglia 3.1.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by host_view.php and certain other files.

  • CVE-2011-3740Sep 23, 2011
    risk 0.00cvss epss 0.01

    FrontAccounting 2.3.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by reporting/includes/fpdi/fpdi2tcpdf_bridge.php and certain other files.

  • CVE-2011-3739Sep 23, 2011
    risk 0.00cvss epss 0.01

    Freeway 1.5 Alpha allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by templates/Freeway/boxes/last_product.php and certain other files.

  • CVE-2011-3738Sep 23, 2011
    risk 0.00cvss epss 0.01

    Feng Office 1.7.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by public/upgrade/templates/layout.php and certain other files.

  • CVE-2011-3737Sep 23, 2011
    risk 0.00cvss epss 0.01

    eyeOS 2.2.0.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by apps/rmail/webmail/program/lib/Net/SMTP.php and certain other files.

  • CVE-2011-3736Sep 23, 2011
    risk 0.00cvss epss 0.01

    ExoPHPDesk 1.2.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by upgrades/upgrade9.php and certain other files.

  • CVE-2011-3735Sep 23, 2011
    risk 0.00cvss epss 0.01

    Escort Agency CMS (aka escort-agency-cms) allows remote attackers to obtain sensitive information via crafted array parameters in a request to a .php file, which reveals the installation path in an error message, as demonstrated by makethumb.php and certain other files.

  • CVE-2011-3734Sep 23, 2011
    risk 0.00cvss epss 0.01

    Energine 2.3.8 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by core/framework/SimpleBuilder.class.php and certain other files.

  • CVE-2011-3733Sep 23, 2011
    risk 0.00cvss epss 0.01

    Elgg 1.7.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by vendors/simpletest/test/visual_test.php and certain other files.

  • CVE-2011-3732Sep 23, 2011
    risk 0.00cvss epss 0.01

    eggBlog 4.1.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by _lib/fckeditor/editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellchecker.php and…

  • CVE-2011-3731Sep 23, 2011
    risk 0.00cvss epss 0.01

    e107 0.7.24 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by e107_plugins/pdf/e107pdf.php and certain other files.

  • CVE-2011-3730Sep 23, 2011
    risk 0.00cvss epss 0.02

    Drupal 7.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/simpletest/tests/upgrade/drupal-6.upload.database.php and certain other files.

  • CVE-2011-3729Sep 23, 2011
    risk 0.00cvss epss 0.01

    dotproject 2.1.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by style/dp-grey-theme/footer.php and certain other files.

  • CVE-2011-3728Sep 23, 2011
    risk 0.00cvss epss 0.01

    Dolphin 7.0.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by xmlrpc/BxDolXMLRPCProfileView.php and certain other files.

  • CVE-2011-3727Sep 23, 2011
    risk 0.00cvss epss 0.02

    DokuWiki 2009-12-25c allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by lib/tpl/index.php and certain other files.

  • CVE-2011-3726Sep 23, 2011
    risk 0.00cvss epss 0.01

    DoceboLMS 4.0.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by views/dummy/show.php and certain other files.

  • CVE-2011-3725Sep 23, 2011
    risk 0.00cvss epss 0.01

    DeluxeBB 1.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by header_html.php.

  • CVE-2011-3724Sep 23, 2011
    risk 0.00cvss epss 0.01

    CubeCart 4.4.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/shipping/USPS/calc.php and certain other files.

  • CVE-2011-3723Sep 23, 2011
    risk 0.00cvss epss 0.01

    Crafty Syntax 3.0.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by README_FILES/livehelp.php and certain other files.

  • CVE-2011-3722Sep 23, 2011
    risk 0.00cvss epss 0.01

    Coppermine Photo Gallery (CPG) 1.5.12 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by include/inspekt.php and certain other files.

  • CVE-2011-3721Sep 23, 2011
    risk 0.00cvss epss 0.01

    concrete 5.4.0.5, 5.4.1, and 5.4.1.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by tools/spellchecker_service.php and certain other files.

  • CVE-2011-3720Sep 23, 2011
    risk 0.00cvss epss 0.01

    conceptcms 5.3.1, 5.3.3, and possibly other versions allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by sys_libs/umlib/um_authserver.inc.php and certain other…

  • CVE-2011-3719Sep 23, 2011
    risk 0.00cvss epss 0.01

    CodeIgniter 1.7.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by system/scaffolding/views/view.php and certain other files.

  • CVE-2011-3718Sep 23, 2011
    risk 0.00cvss epss 0.01

    CMS Made Simple (CMSMS) 1.9.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/TinyMCE/TinyMCE.module.php and certain other files. NOTE: this might…

  • CVE-2011-3717Sep 23, 2011
    risk 0.00cvss epss 0.01

    ClipBucket 2.0.9 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by plugins/signup_captcha/signup_captcha.php and certain other files.

  • CVE-2011-3716Sep 23, 2011
    risk 0.00cvss epss 0.01

    Claroline 1.9.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by work/connector/linker.cnr.php and certain other files.

  • CVE-2011-3715Sep 23, 2011
    risk 0.00cvss epss 0.01

    ClanTiger 1.1.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by widgets/statistics/statistics.php and certain other files.

  • CVE-2011-3714Sep 23, 2011
    risk 0.00cvss epss 0.01

    ClanSphere 2010.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by mods/board/attachment.php.

  • CVE-2011-3713Sep 23, 2011
    risk 0.04cvss epss 0.07

    cFTP r80 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by templates/session_check.php and certain other files.

  • CVE-2011-3712Sep 23, 2011
    risk 0.00cvss epss 0.02

    CakePHP 1.3.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by dispatcher.php and certain other files.

  • CVE-2011-3711Sep 23, 2011
    risk 0.00cvss epss 0.01

    BIGACE 2.7.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by system/libs/javascript.inc.php and certain other files.

  • CVE-2011-3710Sep 23, 2011
    risk 0.00cvss epss 0.01

    bbPress 1.0.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by bb-templates/kakumei/view.php and certain other files.

  • CVE-2011-3709Sep 23, 2011
    risk 0.00cvss epss 0.01

    b2evolution 3.3.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by locales/ru_RU/ru-RU.locale.php and certain other files.

  • CVE-2011-3708Sep 23, 2011
    risk 0.00cvss epss 0.01

    Automne 4.0.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by admin/page-redirect-info.php.

  • CVE-2011-3707Sep 23, 2011
    risk 0.00cvss epss 0.01

    JanRain PHP OpenID library (aka php-openid) 2.2.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by Auth/Yadis/Yadis.php and certain other files.

  • CVE-2011-3706Sep 23, 2011
    risk 0.00cvss epss 0.01

    ATutor 2.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by users/tool_settings.inc.php and certain other files.

  • CVE-2011-3705Sep 23, 2011
    risk 0.00cvss epss 0.01

    Arctic Fox CMS 0.9.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by acp/includes/edit.inc.php and certain other files.

  • CVE-2011-3704Sep 23, 2011
    risk 0.00cvss epss 0.01

    appRain 0.1.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by cron.php.

  • CVE-2011-3703Sep 23, 2011
    risk 0.00cvss epss 0.01

    AneCMS 1.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by widgets/menu/index.php and certain other files.

  • CVE-2011-3702Sep 23, 2011
    risk 0.00cvss epss 0.01

    Ananta Gazelle 1.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/template.php and certain other files.

  • CVE-2011-3701Sep 23, 2011
    risk 0.00cvss epss 0.01

    AlegroCart 1.2.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by common.php and certain other files.

  • CVE-2011-3700Sep 23, 2011
    risk 0.00cvss epss 0.01

    Advanced Electron Forum (AEF) 1.0.8 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by languages/english/deletetopic_lang.php.

  • CVE-2011-3699Sep 23, 2011
    risk 0.00cvss epss 0.01

    John Lim ADOdb Library for PHP 5.11 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by tests/test-active-record.php and certain other files.

  • CVE-2011-3698Sep 23, 2011
    risk 0.00cvss epss 0.01

    AdaptCMS 2.0.2 Beta allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by inc/poll_vote.php and certain other files.

  • CVE-2011-3697Sep 23, 2011
    risk 0.00cvss epss 0.01

    Achievo 1.4.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/graph/jpgraph/jpgraph_radar.php and certain other files.