Search
Total
7597 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2011-3722 | 1 Coppermine-gallery | 1 Coppermine Photo Gallery | 2012-03-13 | 5.0 MEDIUM | N/A |
| Coppermine Photo Gallery (CPG) 1.5.12 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by include/inspekt.php and certain other files. | |||||
| CVE-2011-3721 | 1 Concrete5 | 1 Concrete | 2012-03-13 | 5.0 MEDIUM | N/A |
| concrete 5.4.0.5, 5.4.1, and 5.4.1.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by tools/spellchecker_service.php and certain other files. | |||||
| CVE-2011-3719 | 1 Codeigniter | 1 Codeigniter | 2012-03-13 | 5.0 MEDIUM | N/A |
| CodeIgniter 1.7.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by system/scaffolding/views/view.php and certain other files. | |||||
| CVE-2011-3699 | 1 John Lim | 1 Adodb | 2012-03-13 | 5.0 MEDIUM | N/A |
| John Lim ADOdb Library for PHP 5.11 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by tests/test-active-record.php and certain other files. | |||||
| CVE-2011-3718 | 1 Cmsmadesimple | 1 Cms Made Simple | 2012-03-13 | 5.0 MEDIUM | N/A |
| CMS Made Simple (CMSMS) 1.9.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/TinyMCE/TinyMCE.module.php and certain other files. NOTE: this might overlap CVE-2007-5444. | |||||
| CVE-2011-3700 | 1 Anelectron | 1 Advanced Electron Forum | 2012-03-13 | 5.0 MEDIUM | N/A |
| Advanced Electron Forum (AEF) 1.0.8 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by languages/english/deletetopic_lang.php. | |||||
| CVE-2011-3717 | 1 Clip-bucket | 1 Clipbucket | 2012-03-13 | 5.0 MEDIUM | N/A |
| ClipBucket 2.0.9 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by plugins/signup_captcha/signup_captcha.php and certain other files. | |||||
| CVE-2011-3701 | 1 Alegrocart | 1 Alegrocart | 2012-03-13 | 5.0 MEDIUM | N/A |
| AlegroCart 1.2.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by common.php and certain other files. | |||||
| CVE-2011-3716 | 1 Claroline | 1 Claroline | 2012-03-13 | 5.0 MEDIUM | N/A |
| Claroline 1.9.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by work/connector/linker.cnr.php and certain other files. | |||||
| CVE-2011-3715 | 1 Clantiger | 1 Clantiger | 2012-03-13 | 5.0 MEDIUM | N/A |
| ClanTiger 1.1.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by widgets/statistics/statistics.php and certain other files. | |||||
| CVE-2011-3714 | 1 Csphere | 1 Clansphere | 2012-03-13 | 5.0 MEDIUM | N/A |
| ClanSphere 2010.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by mods/board/attachment.php. | |||||
| CVE-2011-3731 | 1 E107 | 1 E107 | 2012-03-13 | 5.0 MEDIUM | N/A |
| e107 0.7.24 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by e107_plugins/pdf/e107pdf.php and certain other files. | |||||
| CVE-2011-3712 | 1 Cakefoundation | 1 Cakephp | 2012-03-13 | 5.0 MEDIUM | N/A |
| CakePHP 1.3.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by dispatcher.php and certain other files. | |||||
| CVE-2011-3711 | 1 Bigace | 1 Bigace | 2012-03-13 | 5.0 MEDIUM | N/A |
| BIGACE 2.7.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by system/libs/javascript.inc.php and certain other files. | |||||
| CVE-2011-3732 | 1 Eggblog | 1 Eggblog | 2012-03-13 | 5.0 MEDIUM | N/A |
| eggBlog 4.1.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by _lib/fckeditor/editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellchecker.php and certain other files. | |||||
| CVE-2011-3728 | 1 Boonex | 1 Dolphin | 2012-03-13 | 5.0 MEDIUM | N/A |
| Dolphin 7.0.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by xmlrpc/BxDolXMLRPCProfileView.php and certain other files. | |||||
| CVE-2011-3710 | 1 Bbpress | 1 Bbpress | 2012-03-13 | 5.0 MEDIUM | N/A |
| bbPress 1.0.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by bb-templates/kakumei/view.php and certain other files. | |||||
| CVE-2011-3709 | 1 B2evolution | 1 B2evolution | 2012-03-13 | 5.0 MEDIUM | N/A |
| b2evolution 3.3.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by locales/ru_RU/ru-RU.locale.php and certain other files. | |||||
| CVE-2011-3708 | 1 Automne-cms | 1 Automne | 2012-03-13 | 5.0 MEDIUM | N/A |
| Automne 4.0.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by admin/page-redirect-info.php. | |||||
| CVE-2011-3707 | 1 Janrain | 1 Php-openid | 2012-03-13 | 5.0 MEDIUM | N/A |
| JanRain PHP OpenID library (aka php-openid) 2.2.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by Auth/Yadis/Yadis.php and certain other files. | |||||
| CVE-2011-3706 | 1 Atutor | 1 Atutor | 2012-03-13 | 5.0 MEDIUM | N/A |
| ATutor 2.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by users/tool_settings.inc.php and certain other files. | |||||
| CVE-2011-3705 | 1 Michael Armbruster | 1 Arctic Fox Cms | 2012-03-13 | 5.0 MEDIUM | N/A |
| Arctic Fox CMS 0.9.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by acp/includes/edit.inc.php and certain other files. | |||||
| CVE-2011-3704 | 1 Apprain | 1 Apprain | 2012-03-13 | 5.0 MEDIUM | N/A |
| appRain 0.1.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by cron.php. | |||||
| CVE-2011-3702 | 1 Anantasoft | 1 Ananta Gazelle | 2012-03-13 | 5.0 MEDIUM | N/A |
| Ananta Gazelle 1.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/template.php and certain other files. | |||||
| CVE-2011-3734 | 1 Energine | 1 Energine | 2012-03-12 | 5.0 MEDIUM | N/A |
| Energine 2.3.8 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by core/framework/SimpleBuilder.class.php and certain other files. | |||||
| CVE-2011-3736 | 1 Exoscripts | 1 Exophpdesk | 2012-03-12 | 5.0 MEDIUM | N/A |
| ExoPHPDesk 1.2.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by upgrades/upgrade9.php and certain other files. | |||||
| CVE-2011-3737 | 1 Eyeos | 1 Eyeos | 2012-03-12 | 5.0 MEDIUM | N/A |
| eyeOS 2.2.0.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by apps/rmail/webmail/program/lib/Net/SMTP.php and certain other files. | |||||
| CVE-2011-3738 | 1 Fengoffice | 1 Feng Office | 2012-03-12 | 5.0 MEDIUM | N/A |
| Feng Office 1.7.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by public/upgrade/templates/layout.php and certain other files. | |||||
| CVE-2011-3739 | 1 Openfreeway | 1 Freeway | 2012-03-12 | 5.0 MEDIUM | N/A |
| Freeway 1.5 Alpha allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by templates/Freeway/boxes/last_product.php and certain other files. | |||||
| CVE-2011-3740 | 1 Frontaccounting | 1 Frontaccounting | 2012-03-12 | 5.0 MEDIUM | N/A |
| FrontAccounting 2.3.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by reporting/includes/fpdi/fpdi2tcpdf_bridge.php and certain other files. | |||||
| CVE-2011-3741 | 1 Ganglia | 1 Ganglia | 2012-03-12 | 5.0 MEDIUM | N/A |
| Ganglia 3.1.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by host_view.php and certain other files. | |||||
| CVE-2011-3742 | 1 Helpcenterlive | 1 Helpcenter Live | 2012-03-12 | 5.0 MEDIUM | N/A |
| HelpCenter Live 2.1.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/HelpCenter/index.php and certain other files. | |||||
| CVE-2011-3743 | 1 Hesk | 1 Hesk | 2012-03-12 | 5.0 MEDIUM | N/A |
| Hesk 2.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by inc/footer.inc.php and certain other files. | |||||
| CVE-2011-3744 | 1 Htmlpurifier | 1 Html Purifier | 2012-03-12 | 5.0 MEDIUM | N/A |
| HTML Purifier 4.2.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by tests/PHPT/Reporter/SimpleTest.php and certain other files. | |||||
| CVE-2011-3745 | 1 Hycus | 1 Hycus Cms | 2012-03-12 | 5.0 MEDIUM | N/A |
| HycusCMS 1.0.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by templates/hycus_template/template.php. | |||||
| CVE-2011-3746 | 1 Jcow | 1 Jcow | 2012-03-12 | 5.0 MEDIUM | N/A |
| Jcow 4.2.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by themes/default/page.tpl.php and certain other files. | |||||
| CVE-2011-3747 | 1 Joomla | 1 Joomla\! | 2012-03-12 | 5.0 MEDIUM | N/A |
| Joomla! 1.6.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by libraries/phpmailer/language/phpmailer.lang-joomla.php. | |||||
| CVE-2011-3748 | 1 Kamads Classifieds | 1 2 B3 | 2012-03-12 | 5.0 MEDIUM | N/A |
| Kamads Classifieds 2_B3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by V2A_XHTML/style/view.php and certain other files. | |||||
| CVE-2011-3749 | 1 Maptools | 1 Ka-map | 2012-03-12 | 5.0 MEDIUM | N/A |
| ka-Map 1.0-20070205 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by test.php and certain other files. | |||||
| CVE-2011-3750 | 1 Kplaylist | 1 Kplaylist | 2012-03-12 | 5.0 MEDIUM | N/A |
| kPlaylist 1.8.502 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by getid3/getid3/write.id3v1.php and certain other files. | |||||
| CVE-2011-3751 | 1 Lifetype | 1 Lifetype | 2012-03-12 | 5.0 MEDIUM | N/A |
| LifeType 1.2.10 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by plugins/badbehavior/pluginbadbehavior.class.php. | |||||
| CVE-2011-3752 | 1 Limesurvey | 1 Limesurvey | 2012-03-12 | 5.0 MEDIUM | N/A |
| LimeSurvey 1.90+ build9642-20101214 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by admin/statistics.php and certain other files. | |||||
| CVE-2011-3753 | 1 Linpha | 1 Linpha | 2012-03-12 | 5.0 MEDIUM | N/A |
| LinPHA 1.3.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by viewer.php and certain other files. | |||||
| CVE-2011-3754 | 1 Mambo-foundation | 1 Mambo | 2012-03-12 | 5.0 MEDIUM | N/A |
| Mambo 4.6.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by includes/sef.php and certain other files. | |||||
| CVE-2011-3756 | 1 Microblog | 1 Microblog | 2012-03-12 | 5.0 MEDIUM | N/A |
| MicroBlog 0.9.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by init.php and certain other files. | |||||
| CVE-2011-3757 | 1 Moodle | 1 Moodle | 2012-03-12 | 5.0 MEDIUM | N/A |
| Moodle 2.0.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by webservice/xmlrpc/locallib.php and certain other files. | |||||
| CVE-2011-3758 | 1 Moundlabs | 1 \ | 2012-03-12 | 5.0 MEDIUM | N/A |
| ::mound:: 2.1.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by lib/smarty/libs/sysplugins/smarty_internal_template.php and certain other files. | |||||
| CVE-2011-3759 | 1 Mybb | 1 Mybb | 2012-03-12 | 5.0 MEDIUM | N/A |
| MyBB (aka MyBulletinBoard) 1.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by inc/3rdparty/diff/Diff/ThreeWay.php and certain other files. | |||||
| CVE-2011-3733 | 1 Elgg | 1 Elgg | 2012-03-12 | 5.0 MEDIUM | N/A |
| Elgg 1.7.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by vendors/simpletest/test/visual_test.php and certain other files. | |||||
| CVE-2011-3735 | 1 Escortwebsitedesign | 1 Escort-agency-cms | 2012-03-12 | 5.0 MEDIUM | N/A |
| Escort Agency CMS (aka escort-agency-cms) allows remote attackers to obtain sensitive information via crafted array parameters in a request to a .php file, which reveals the installation path in an error message, as demonstrated by makethumb.php and certain other files. | |||||
