Total
6955 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2011-3246 | 1 Apple | 3 Iphone Os, Mac Os X, Mac Os X Server | 2017-08-28 | 5.0 MEDIUM | N/A |
CFNetwork in Apple iOS before 5.0.1 and Mac OS X 10.7 before 10.7.2 does not properly parse URLs, which allows remote attackers to trigger visits to unintended web sites, and transmission of cookies to unintended web sites, via a crafted (1) http or (2) https URL. | |||||
CVE-2011-3264 | 1 Zabbix | 1 Zabbix | 2017-08-28 | 5.0 MEDIUM | N/A |
Zabbix before 1.8.6 allows remote attackers to obtain sensitive information via an invalid srcfld2 parameter to popup.php, which reveals the installation path in an error message. | |||||
CVE-2011-3265 | 1 Zabbix | 1 Zabbix | 2017-08-28 | 5.0 MEDIUM | N/A |
popup.php in Zabbix before 1.8.7 allows remote attackers to read the contents of arbitrary database tables via a modified srctbl parameter. | |||||
CVE-2011-3388 | 1 Opera | 1 Opera Browser | 2017-08-28 | 4.3 MEDIUM | N/A |
Opera before 11.51 allows remote attackers to cause an insecure site to appear secure or trusted via unspecified actions related to Extended Validation and loading content from trusted sources in an unspecified sequence that causes the address field and page information dialog to contain security information based on the trusted site, instead of the insecure site. | |||||
CVE-2011-3431 | 1 Apple | 1 Iphone Os | 2017-08-28 | 2.1 LOW | N/A |
The Home screen component in Apple iOS before 5 does not properly support a certain application-switching gesture, which might allow physically proximate attackers to obtain sensitive state information by watching the device's screen. | |||||
CVE-2011-3427 | 1 Apple | 2 Apple Tv, Iphone Os | 2017-08-28 | 2.6 LOW | N/A |
The Data Security component in Apple iOS before 5 and Apple TV before 4.4 does not properly restrict use of the MD5 hash algorithm within X.509 certificates, which makes it easier for man-in-the-middle attackers to spoof servers or obtain sensitive information via a crafted certificate. | |||||
CVE-2011-3770 | 1 Phpalbum | 1 Phpalbum | 2017-08-28 | 5.0 MEDIUM | N/A |
phpAlbum 0.4.1.14 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by themes/Flowing_Dark/parameters.tpl.php and certain other files. | |||||
CVE-2011-3580 | 1 Icewarp | 1 Mail Server | 2017-08-28 | 5.0 MEDIUM | N/A |
IceWarp WebMail in IceWarp Mail Server before 10.3.3 allows remote attackers to obtain configuration information via a direct request to the /server URI, which triggers a call to the phpinfo function. | |||||
CVE-2011-3713 | 1 Powerdrummer | 1 Cftp | 2017-08-28 | 5.0 MEDIUM | N/A |
cFTP r80 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by templates/session_check.php and certain other files. | |||||
CVE-2011-3760 | 1 Nucleuscms | 1 Nucleus Cms | 2017-08-28 | 5.0 MEDIUM | N/A |
Nucleus 3.61 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by xmlrpc/api_nucleus.inc.php and certain other files. | |||||
CVE-2011-3761 | 1 Dietrich Ayala | 1 Nusoap | 2017-08-28 | 5.0 MEDIUM | N/A |
NuSOAP 0.9.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by nuSOAP/classes/class.wsdl.php and certain other files. | |||||
CVE-2011-3762 | 1 Open-blog | 1 Openblog | 2017-08-28 | 5.0 MEDIUM | N/A |
OpenBlog 1.2.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by system/scaffolding/views/view.php and certain other files. | |||||
CVE-2011-3763 | 1 Opencart | 1 Opencart | 2017-08-28 | 5.0 MEDIUM | N/A |
OpenCart 1.4.9.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by system/startup.php and certain other files. | |||||
CVE-2011-3764 | 1 Opendocman | 1 Opendocman | 2017-08-28 | 5.0 MEDIUM | N/A |
OpenDocMan 1.2.6-svn-2011-01-21 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by User_Perms_class.php and certain other files. | |||||
CVE-2011-3765 | 1 Open-realty | 1 Open-realty | 2017-08-28 | 5.0 MEDIUM | N/A |
Open-Realty 2.5.8 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by install/versions/upgrade_115.inc.php and certain other files. | |||||
CVE-2011-3766 | 1 Orangehrm | 1 Orangehrm | 2017-08-28 | 5.0 MEDIUM | N/A |
OrangeHRM 2.6.0.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by themes/orange/menu/Menu.php and certain other files. | |||||
CVE-2011-3767 | 1 Oscommerce | 1 Oscommerce | 2017-08-28 | 5.0 MEDIUM | N/A |
osCommerce 3.0a5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by redirect.php. | |||||
CVE-2011-3768 | 1 Phorum | 1 Phorum | 2017-08-28 | 5.0 MEDIUM | N/A |
Phorum 5.2.15a allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by css.php and certain other files. | |||||
CVE-2011-3769 | 1 Blondish | 1 Phpads | 2017-08-28 | 5.0 MEDIUM | N/A |
PHPads 2.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by ads.inc.php. | |||||
CVE-2011-3771 | 1 Gnu | 1 Phpbook | 2017-08-28 | 5.0 MEDIUM | N/A |
phpBook 2.1.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by doc/update_smilies_1.50-1.60.php and certain other files. |