CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2011-3325

    Last Modified: 11 Apr 2025

    ospf_packet.c in ospfd in Quagga before 0.99.19 allows remote attackers to cause a denial of service (daemon crash) via (1) a 0x0a type field in an IPv4 packet header or (2) a truncated IPv4 Hello packet.

    Published: 26 Sept 2011
    5
    Medium

    CVE-2011-3326

    Last Modified: 11 Apr 2025

    The ospf_flood function in ospf_flood.c in ospfd in Quagga before 0.99.19 allows remote attackers to cause a denial of service (daemon crash) via an invalid Link State Advertisement (LSA) type in an IPv4 Link State Update message.

    Published: 26 Sept 2011
    5
    Medium

    CVE-2011-5062

    Last Modified: 11 Apr 2025

    The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check qop values, which might allow remote attackers to bypass intended integrity-protection requirements via a qop=auth value, a different vulnerability than CVE-2011-1184.

    Published: 26 Sept 2011
    Unknown

    CVE-2004-2770

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2011-3389. Reason: This candidate is a duplicate of CVE-2011-3389. Notes: All CVE users should reference CVE-2011-3389 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 25 Sept 2011
    5
    Medium

    CVE-2011-3791

    Last Modified: 11 Apr 2025

    Piwik 1.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by plugins/Widgetize/Widgetize.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3760

    Last Modified: 11 Apr 2025

    Nucleus 3.61 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by xmlrpc/api_nucleus.inc.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3761

    Last Modified: 11 Apr 2025

    NuSOAP 0.9.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by nuSOAP/classes/class.wsdl.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3762

    Last Modified: 11 Apr 2025

    OpenBlog 1.2.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by system/scaffolding/views/view.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3763

    Last Modified: 11 Apr 2025

    OpenCart 1.4.9.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by system/startup.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3764

    Last Modified: 11 Apr 2025

    OpenDocMan 1.2.6-svn-2011-01-21 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by User_Perms_class.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3765

    Last Modified: 11 Apr 2025

    Open-Realty 2.5.8 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by install/versions/upgrade_115.inc.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3767

    Last Modified: 11 Apr 2025

    osCommerce 3.0a5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by redirect.php.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3768

    Last Modified: 11 Apr 2025

    Phorum 5.2.15a allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by css.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3769

    Last Modified: 11 Apr 2025

    PHPads 2.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by ads.inc.php.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3770

    Last Modified: 11 Apr 2025

    phpAlbum 0.4.1.14 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by themes/Flowing_Dark/parameters.tpl.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3771

    Last Modified: 11 Apr 2025

    phpBook 2.1.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by doc/update_smilies_1.50-1.60.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3772

    Last Modified: 11 Apr 2025

    phpCollab 2.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by topics/noti_newtopic.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3773

    Last Modified: 11 Apr 2025

    PHPDevShell 3.0.0-Beta-4b allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by gzip.php.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3774

    Last Modified: 11 Apr 2025

    php Easy Survey Package (phpESP) 2.1.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by public/landing.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3776

    Last Modified: 11 Apr 2025

    phpFormGenerator 2.09 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by forms/process.php.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3777

    Last Modified: 11 Apr 2025

    phpFreeChat 1.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by themes/zilveer/style.css.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3778

    Last Modified: 11 Apr 2025

    PhpGedView 4.2.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by serviceClientTest.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3779

    Last Modified: 11 Apr 2025

    PhpHostBot 2.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by admin/create_acct.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3780

    Last Modified: 11 Apr 2025

    PHP iCalendar 2.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by rss/rss_common.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3781

    Last Modified: 11 Apr 2025

    PHPIDS 0.6.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by tests/IDS/VersionTest.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3782

    Last Modified: 11 Apr 2025

    phpLD 2-151.2.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by libs/smarty/Smarty_Compiler.class.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3784

    Last Modified: 11 Apr 2025

    Francisco Burzi PHP-Nuke 8.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by themes/Odyssey/theme.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3785

    Last Modified: 11 Apr 2025

    PHP Point Of Sale (POS) 10.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by system/scaffolding/views/view.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3786

    Last Modified: 11 Apr 2025

    PHProjekt 6.0.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by Setup/Controllers/IndexController.php.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3787

    Last Modified: 11 Apr 2025

    phpScheduleIt 1.2.12 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by templates/schedule.template.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3788

    Last Modified: 11 Apr 2025

    PhpSecInfo 0.2.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by Test/Test_Suhosin.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3789

    Last Modified: 11 Apr 2025

    phpwcms 1.4.7 r412 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by template/inc_script/frontend_render/disabled/majonavi.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3792

    Last Modified: 11 Apr 2025

    Pixelpost 1.7.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by includes/functions_feeds.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3794

    Last Modified: 11 Apr 2025

    Pligg CMS 1.1.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by widgets/statistics/init.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3795

    Last Modified: 11 Apr 2025

    Podcast Generator 1.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by core/themes.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3796

    Last Modified: 11 Apr 2025

    PrestaShop 1.4.0.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by product-sort.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3797

    Last Modified: 11 Apr 2025

    ProjectPier 0.8.0.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by public/upgrade/templates/layout.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3798

    Last Modified: 11 Apr 2025

    Rapid Leech 2.3-v42-svn322 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by classes/pear.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3799

    Last Modified: 11 Apr 2025

    ReOS 2.0.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by padmin/blocks/vergal.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3800

    Last Modified: 11 Apr 2025

    Serendipity 1.5.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by templates/newspaper/layout.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3802

    Last Modified: 11 Apr 2025

    StatusNet 0.9.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by tpl/index.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3803

    Last Modified: 11 Apr 2025

    SugarCRM 6.1.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by themes/Sugar5/layout_utils.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3804

    Last Modified: 11 Apr 2025

    SweetRice 0.7.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by _plugin/tiny_mce/plugins/advimage/images.php.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3805

    Last Modified: 11 Apr 2025

    TaskFreak! multi-mysql-0.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by include/language/zh/register_info.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3806

    Last Modified: 11 Apr 2025

    TCExam 11.1.015 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by public/code/tce_page_footer.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3807

    Last Modified: 11 Apr 2025

    Textpattern 4.2.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by lib/txplib_db.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3808

    Last Modified: 11 Apr 2025

    The Bug Genie 2.1.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/svn_integration/config.inc.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3810

    Last Modified: 11 Apr 2025

    TinyWebGallery (TWG) 1.8.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by i_frames/i_register.php.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3811

    Last Modified: 11 Apr 2025

    TomatoCart 1.1.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by templates/system/offline.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3812

    Last Modified: 11 Apr 2025

    Vanilla 2.0.16 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by plugins/Minify/min/utils.php and certain other files.

    Published: 24 Sept 2011