Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2011-3562 | 1 Oracle | 1 Fusion Middleware | 2017-08-28 | 4.3 MEDIUM | N/A |
Unspecified vulnerability in the Portal component in Oracle Fusion Middleware 11.1.1.5, 11.1.1.6, and 11.1.2.0 allows remote attackers to affect integrity via unknown vectors. | |||||
CVE-2011-3575 | 1 Ibm | 1 Lotus Domino | 2017-08-28 | 9.0 HIGH | N/A |
Stack-based buffer overflow in the NSFComputeEvaluateExt function in Nnotes.dll in IBM Lotus Domino 8.5.2 allows remote authenticated users to execute arbitrary code via a long tHPRAgentName parameter in an fmHttpPostRequest OpenForm action to WebAdmin.nsf. | |||||
CVE-2011-3579 | 1 Icewarp | 1 Mail Server | 2017-08-28 | 6.4 MEDIUM | N/A |
server/webmail.php in IceWarp WebMail in IceWarp Mail Server before 10.3.3 allows remote attackers to read arbitrary files, and possibly send HTTP requests to intranet servers or cause a denial of service (CPU and memory consumption), via an XML external entity declaration in conjunction with an entity reference. | |||||
CVE-2011-3580 | 1 Icewarp | 1 Mail Server | 2017-08-28 | 5.0 MEDIUM | N/A |
IceWarp WebMail in IceWarp Mail Server before 10.3.3 allows remote attackers to obtain configuration information via a direct request to the /server URI, which triggers a call to the phpinfo function. | |||||
CVE-2011-3615 | 1 Simplemachines | 1 Smf | 2017-08-28 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Simple Machines Forum (SMF) before 1.1.15 and 2.x before 2.0.1 allow remote attackers to execute arbitrary SQL commands via vectors involving a (1) HTML entity or (2) display name. NOTE: some of these details are obtained from third party information. | |||||
CVE-2011-3667 | 1 Mozilla | 1 Bugzilla | 2017-08-28 | 6.8 MEDIUM | N/A |
The User.offer_account_by_email WebService method in Bugzilla 2.x and 3.x before 3.4.13, 3.5.x and 3.6.x before 3.6.7, 3.7.x and 4.0.x before 4.0.3, and 4.1.x through 4.1.3, when createemailregexp is not empty, does not properly handle user_can_create_account settings, which allows remote attackers to create user accounts by leveraging a token contained in an e-mail message. | |||||
CVE-2011-3713 | 1 Powerdrummer | 1 Cftp | 2017-08-28 | 5.0 MEDIUM | N/A |
cFTP r80 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by templates/session_check.php and certain other files. | |||||
CVE-2011-3760 | 1 Nucleuscms | 1 Nucleus Cms | 2017-08-28 | 5.0 MEDIUM | N/A |
Nucleus 3.61 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by xmlrpc/api_nucleus.inc.php and certain other files. | |||||
CVE-2011-3761 | 1 Dietrich Ayala | 1 Nusoap | 2017-08-28 | 5.0 MEDIUM | N/A |
NuSOAP 0.9.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by nuSOAP/classes/class.wsdl.php and certain other files. | |||||
CVE-2011-3762 | 1 Open-blog | 1 Openblog | 2017-08-28 | 5.0 MEDIUM | N/A |
OpenBlog 1.2.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by system/scaffolding/views/view.php and certain other files. | |||||
CVE-2011-3763 | 1 Opencart | 1 Opencart | 2017-08-28 | 5.0 MEDIUM | N/A |
OpenCart 1.4.9.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by system/startup.php and certain other files. | |||||
CVE-2011-3764 | 1 Opendocman | 1 Opendocman | 2017-08-28 | 5.0 MEDIUM | N/A |
OpenDocMan 1.2.6-svn-2011-01-21 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by User_Perms_class.php and certain other files. | |||||
CVE-2011-3765 | 1 Open-realty | 1 Open-realty | 2017-08-28 | 5.0 MEDIUM | N/A |
Open-Realty 2.5.8 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by install/versions/upgrade_115.inc.php and certain other files. | |||||
CVE-2011-3766 | 1 Orangehrm | 1 Orangehrm | 2017-08-28 | 5.0 MEDIUM | N/A |
OrangeHRM 2.6.0.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by themes/orange/menu/Menu.php and certain other files. | |||||
CVE-2011-3767 | 1 Oscommerce | 1 Oscommerce | 2017-08-28 | 5.0 MEDIUM | N/A |
osCommerce 3.0a5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by redirect.php. | |||||
CVE-2011-3768 | 1 Phorum | 1 Phorum | 2017-08-28 | 5.0 MEDIUM | N/A |
Phorum 5.2.15a allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by css.php and certain other files. | |||||
CVE-2011-3769 | 1 Blondish | 1 Phpads | 2017-08-28 | 5.0 MEDIUM | N/A |
PHPads 2.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by ads.inc.php. | |||||
CVE-2011-3770 | 1 Phpalbum | 1 Phpalbum | 2017-08-28 | 5.0 MEDIUM | N/A |
phpAlbum 0.4.1.14 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by themes/Flowing_Dark/parameters.tpl.php and certain other files. | |||||
CVE-2011-3771 | 1 Gnu | 1 Phpbook | 2017-08-28 | 5.0 MEDIUM | N/A |
phpBook 2.1.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by doc/update_smilies_1.50-1.60.php and certain other files. | |||||
CVE-2011-3773 | 1 Phpdevshell | 1 Phpdevshell | 2017-08-28 | 5.0 MEDIUM | N/A |
PHPDevShell 3.0.0-Beta-4b allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by gzip.php. |