Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2011-3725 | 1 Deluxebb | 1 Deluxebb | 2012-03-12 | 5.0 MEDIUM | N/A |
DeluxeBB 1.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by header_html.php. | |||||
CVE-2011-3726 | 1 Docebo | 1 Docebolms | 2012-03-12 | 5.0 MEDIUM | N/A |
DoceboLMS 4.0.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by views/dummy/show.php and certain other files. | |||||
CVE-2011-3728 | 1 Boonex | 1 Dolphin | 2012-03-12 | 5.0 MEDIUM | N/A |
Dolphin 7.0.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by xmlrpc/BxDolXMLRPCProfileView.php and certain other files. | |||||
CVE-2011-3729 | 1 Dotproject | 1 Dotproject | 2012-03-12 | 5.0 MEDIUM | N/A |
dotproject 2.1.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by style/dp-grey-theme/footer.php and certain other files. | |||||
CVE-2011-3730 | 1 Drupal | 1 Drupal | 2012-03-12 | 5.0 MEDIUM | N/A |
Drupal 7.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/simpletest/tests/upgrade/drupal-6.upload.database.php and certain other files. | |||||
CVE-2011-3731 | 1 E107 | 1 E107 | 2012-03-12 | 5.0 MEDIUM | N/A |
e107 0.7.24 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by e107_plugins/pdf/e107pdf.php and certain other files. | |||||
CVE-2011-3732 | 1 Eggblog | 1 Eggblog | 2012-03-12 | 5.0 MEDIUM | N/A |
eggBlog 4.1.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by _lib/fckeditor/editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellchecker.php and certain other files. | |||||
CVE-2012-1472 | 1 Vmware | 1 Vcenter Chargeback Manager | 2012-03-12 | 6.4 MEDIUM | N/A |
VMware vCenter Chargeback Manager (aka CBM) before 2.0.1 does not properly handle XML API requests, which allows remote attackers to read arbitrary files or cause a denial of service via unspecified vectors. | |||||
CVE-2011-2772 | 1 Mahara | 1 Mahara | 2012-03-11 | 5.0 MEDIUM | N/A |
The get_dataroot_image_path function in lib/file.php in Mahara before 1.4.1 does not properly validate uploaded image files, which allows remote attackers to cause a denial of service (memory consumption) via a (1) large or (2) invalid image. | |||||
CVE-2011-3616 | 1 Conky | 1 Conky | 2012-03-11 | 6.3 MEDIUM | N/A |
The getSkillname function in the eve module in Conky 1.8.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on /tmp/.cesf. | |||||
CVE-2011-3733 | 1 Elgg | 1 Elgg | 2012-03-11 | 5.0 MEDIUM | N/A |
Elgg 1.7.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by vendors/simpletest/test/visual_test.php and certain other files. | |||||
CVE-2011-3734 | 1 Energine | 1 Energine | 2012-03-11 | 5.0 MEDIUM | N/A |
Energine 2.3.8 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by core/framework/SimpleBuilder.class.php and certain other files. | |||||
CVE-2011-3735 | 1 Escortwebsitedesign | 1 Escort-agency-cms | 2012-03-11 | 5.0 MEDIUM | N/A |
Escort Agency CMS (aka escort-agency-cms) allows remote attackers to obtain sensitive information via crafted array parameters in a request to a .php file, which reveals the installation path in an error message, as demonstrated by makethumb.php and certain other files. | |||||
CVE-2011-3736 | 1 Exoscripts | 1 Exophpdesk | 2012-03-11 | 5.0 MEDIUM | N/A |
ExoPHPDesk 1.2.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by upgrades/upgrade9.php and certain other files. | |||||
CVE-2011-3737 | 1 Eyeos | 1 Eyeos | 2012-03-11 | 5.0 MEDIUM | N/A |
eyeOS 2.2.0.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by apps/rmail/webmail/program/lib/Net/SMTP.php and certain other files. | |||||
CVE-2011-3738 | 1 Fengoffice | 1 Feng Office | 2012-03-11 | 5.0 MEDIUM | N/A |
Feng Office 1.7.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by public/upgrade/templates/layout.php and certain other files. | |||||
CVE-2011-3739 | 1 Openfreeway | 1 Freeway | 2012-03-11 | 5.0 MEDIUM | N/A |
Freeway 1.5 Alpha allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by templates/Freeway/boxes/last_product.php and certain other files. | |||||
CVE-2011-3740 | 1 Frontaccounting | 1 Frontaccounting | 2012-03-11 | 5.0 MEDIUM | N/A |
FrontAccounting 2.3.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by reporting/includes/fpdi/fpdi2tcpdf_bridge.php and certain other files. | |||||
CVE-2011-3741 | 1 Ganglia | 1 Ganglia | 2012-03-11 | 5.0 MEDIUM | N/A |
Ganglia 3.1.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by host_view.php and certain other files. | |||||
CVE-2011-3742 | 1 Helpcenterlive | 1 Helpcenter Live | 2012-03-11 | 5.0 MEDIUM | N/A |
HelpCenter Live 2.1.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/HelpCenter/index.php and certain other files. |