VYPR

CVEs

386,405 total · page 6781 of 7,729

  • CVE-2011-3811Sep 24, 2011
    risk 0.00cvss —epss 0.01

    TomatoCart 1.1.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by templates/system/offline.php and certain other files.

  • CVE-2011-3810Sep 24, 2011
    risk 0.00cvss —epss 0.01

    TinyWebGallery (TWG) 1.8.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by i_frames/i_register.php.

  • CVE-2011-3809Sep 24, 2011
    risk 0.00cvss —epss 0.01

    TheHostingTool (THT) 1.2.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by includes/pear/Mail/smtp.php and certain other files.

  • CVE-2011-3808Sep 24, 2011
    risk 0.00cvss —epss 0.01

    The Bug Genie 2.1.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/svn_integration/config.inc.php and certain other files.

  • CVE-2011-3807Sep 24, 2011
    risk 0.00cvss —epss 0.01

    Textpattern 4.2.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by lib/txplib_db.php and certain other files.

  • CVE-2011-3806Sep 24, 2011
    risk 0.00cvss —epss 0.01

    TCExam 11.1.015 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by public/code/tce_page_footer.php and certain other files.

  • CVE-2011-3805Sep 24, 2011
    risk 0.00cvss —epss 0.01

    TaskFreak! multi-mysql-0.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by include/language/zh/register_info.php and certain other files.

  • CVE-2011-3804Sep 24, 2011
    risk 0.00cvss —epss 0.01

    SweetRice 0.7.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by _plugin/tiny_mce/plugins/advimage/images.php.

  • CVE-2011-3803Sep 24, 2011
    risk 0.00cvss —epss 0.01

    SugarCRM 6.1.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by themes/Sugar5/layout_utils.php and certain other files.

  • CVE-2011-3802Sep 24, 2011
    risk 0.00cvss —epss 0.01

    StatusNet 0.9.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by tpl/index.php and certain other files.

  • CVE-2011-3801Sep 24, 2011
    risk 0.00cvss —epss 0.01

    SimpleTest 1.0.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by test/visual_test.php and certain other files.

  • CVE-2011-3800Sep 24, 2011
    risk 0.00cvss —epss 0.01

    Serendipity 1.5.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by templates/newspaper/layout.php and certain other files.

  • CVE-2011-3799Sep 24, 2011
    risk 0.00cvss —epss 0.01

    ReOS 2.0.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by padmin/blocks/vergal.php and certain other files.

  • CVE-2011-3798Sep 24, 2011
    risk 0.00cvss —epss 0.01

    Rapid Leech 2.3-v42-svn322 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by classes/pear.php and certain other files.

  • CVE-2011-3797Sep 24, 2011
    risk 0.00cvss —epss 0.01

    ProjectPier 0.8.0.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by public/upgrade/templates/layout.php and certain other files.

  • CVE-2011-3796Sep 24, 2011
    risk 0.00cvss —epss 0.02

    PrestaShop 1.4.0.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by product-sort.php and certain other files.

  • CVE-2011-3795Sep 24, 2011
    risk 0.00cvss —epss 0.01

    Podcast Generator 1.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by core/themes.php and certain other files.

  • CVE-2011-3794Sep 24, 2011
    risk 0.00cvss —epss 0.01

    Pligg CMS 1.1.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by widgets/statistics/init.php and certain other files.

  • CVE-2011-3793Sep 24, 2011
    risk 0.00cvss —epss 0.02

    Pixie 1.04 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by admin/modules/static.php and certain other files.

  • CVE-2011-3792Sep 24, 2011
    risk 0.00cvss —epss 0.01

    Pixelpost 1.7.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by includes/functions_feeds.php and certain other files.

  • CVE-2011-3791Sep 24, 2011
    risk 0.00cvss —epss 0.01

    Piwik 1.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by plugins/Widgetize/Widgetize.php and certain other files.

  • CVE-2011-3790Sep 24, 2011
    risk 0.00cvss —epss 0.01

    Piwigo 2.1.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by tools/metadata.php and certain other files.

  • CVE-2011-3789Sep 24, 2011
    risk 0.00cvss —epss 0.01

    phpwcms 1.4.7 r412 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by template/inc_script/frontend_render/disabled/majonavi.php and certain other files.

  • CVE-2011-3788Sep 24, 2011
    risk 0.00cvss —epss 0.01

    PhpSecInfo 0.2.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by Test/Test_Suhosin.php and certain other files.

  • CVE-2011-3787Sep 24, 2011
    risk 0.00cvss —epss 0.01

    phpScheduleIt 1.2.12 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by templates/schedule.template.php and certain other files.

  • CVE-2011-3786Sep 24, 2011
    risk 0.00cvss —epss 0.01

    PHProjekt 6.0.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by Setup/Controllers/IndexController.php.

  • CVE-2011-3785Sep 24, 2011
    risk 0.00cvss —epss 0.01

    PHP Point Of Sale (POS) 10.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by system/scaffolding/views/view.php and certain other files.

  • CVE-2011-3784Sep 24, 2011
    risk 0.00cvss —epss 0.01

    Francisco Burzi PHP-Nuke 8.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by themes/Odyssey/theme.php and certain other files.

  • CVE-2011-3783Sep 24, 2011
    risk 0.00cvss —epss 0.01

    phpMyFAQ 2.6.13 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by lang/language_uk.php and certain other files.

  • CVE-2011-3782Sep 24, 2011
    risk 0.00cvss —epss 0.01

    phpLD 2-151.2.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by libs/smarty/Smarty_Compiler.class.php and certain other files.

  • CVE-2011-3781Sep 24, 2011
    risk 0.00cvss —epss 0.01

    PHPIDS 0.6.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by tests/IDS/VersionTest.php and certain other files.

  • CVE-2011-3780Sep 24, 2011
    risk 0.00cvss —epss 0.01

    PHP iCalendar 2.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by rss/rss_common.php and certain other files.

  • CVE-2011-3779Sep 24, 2011
    risk 0.00cvss —epss 0.01

    PhpHostBot 2.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by admin/create_acct.php and certain other files.

  • CVE-2011-3778Sep 24, 2011
    risk 0.00cvss —epss 0.01

    PhpGedView 4.2.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by serviceClientTest.php and certain other files.

  • CVE-2011-3777Sep 24, 2011
    risk 0.00cvss —epss 0.01

    phpFreeChat 1.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by themes/zilveer/style.css.php and certain other files.

  • CVE-2011-3776Sep 24, 2011
    risk 0.00cvss —epss 0.01

    phpFormGenerator 2.09 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by forms/process.php.

  • CVE-2011-3775Sep 24, 2011
    risk 0.00cvss —epss 0.01

    PHPfileNavigator 2.3.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by xestion/varios/logs.inc.php and certain other files.

  • CVE-2011-3774Sep 24, 2011
    risk 0.00cvss —epss 0.01

    php Easy Survey Package (phpESP) 2.1.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by public/landing.php and certain other files.

  • CVE-2011-3773Sep 24, 2011
    risk 0.00cvss —epss 0.01

    PHPDevShell 3.0.0-Beta-4b allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by gzip.php.

  • CVE-2011-3772Sep 24, 2011
    risk 0.00cvss —epss 0.01

    phpCollab 2.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by topics/noti_newtopic.php and certain other files.

  • CVE-2011-3771Sep 24, 2011
    risk 0.00cvss —epss 0.01

    phpBook 2.1.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by doc/update_smilies_1.50-1.60.php and certain other files.

  • CVE-2011-3770Sep 24, 2011
    risk 0.00cvss —epss 0.01

    phpAlbum 0.4.1.14 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by themes/Flowing_Dark/parameters.tpl.php and certain other files.

  • CVE-2011-3769Sep 24, 2011
    risk 0.00cvss —epss 0.01

    PHPads 2.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by ads.inc.php.

  • CVE-2011-3768Sep 24, 2011
    risk 0.00cvss —epss 0.01

    Phorum 5.2.15a allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by css.php and certain other files.

  • CVE-2011-3767Sep 24, 2011
    risk 0.00cvss —epss 0.01

    osCommerce 3.0a5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by redirect.php.

  • CVE-2011-3766Sep 24, 2011
    risk 0.00cvss —epss 0.01

    OrangeHRM 2.6.0.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by themes/orange/menu/Menu.php and certain other files.

  • CVE-2011-3765Sep 24, 2011
    risk 0.00cvss —epss 0.01

    Open-Realty 2.5.8 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by install/versions/upgrade_115.inc.php and certain other files.

  • CVE-2011-3764Sep 24, 2011
    risk 0.00cvss —epss 0.01

    OpenDocMan 1.2.6-svn-2011-01-21 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by User_Perms_class.php and certain other files.

  • CVE-2011-3763Sep 24, 2011
    risk 0.00cvss —epss 0.02

    OpenCart 1.4.9.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by system/startup.php and certain other files.

  • CVE-2011-3762Sep 24, 2011
    risk 0.00cvss —epss 0.01

    OpenBlog 1.2.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by system/scaffolding/views/view.php and certain other files.