CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2011-3813

    Last Modified: 11 Apr 2025

    Virtual War (aka VWar) 1.5.0r15 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by includes/language/dutch.inc.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3814

    Last Modified: 11 Apr 2025

    WebCalendar 1.2.3, and other versions before 1.2.5, allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by ws/user_mod.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3815

    Last Modified: 11 Apr 2025

    WeBid 1.0.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by js/calendar.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3816

    Last Modified: 11 Apr 2025

    WEBinsta mailing list manager 1.3e allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by install/install3.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3818

    Last Modified: 11 Apr 2025

    WordPress 2.9.2 and 3.0.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by wp-admin/includes/user.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3819

    Last Modified: 11 Apr 2025

    WoW Server Status 4.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by status.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3820

    Last Modified: 11 Apr 2025

    WSN Software 6.0.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by includes/prestart.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3821

    Last Modified: 11 Apr 2025

    xajax 0.6 beta1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by xajax_core/plugin_layer/xajaxScriptPlugin.inc.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3822

    Last Modified: 11 Apr 2025

    XOOPS 2.5.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/system/xoops_version.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3823

    Last Modified: 11 Apr 2025

    Yamamah 1.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by themes/default/index.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3824

    Last Modified: 11 Apr 2025

    Your Own URL Shortener (YOURLS) 1.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by includes/auth.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3826

    Last Modified: 11 Apr 2025

    Zikula 1.2.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by themes/voodoodolly/version.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3775

    Last Modified: 11 Apr 2025

    PHPfileNavigator 2.3.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by xestion/varios/logs.inc.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3790

    Last Modified: 11 Apr 2025

    Piwigo 2.1.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by tools/metadata.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3766

    Last Modified: 11 Apr 2025

    OrangeHRM 2.6.0.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by themes/orange/menu/Menu.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3783

    Last Modified: 11 Apr 2025

    phpMyFAQ 2.6.13 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by lang/language_uk.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3793

    Last Modified: 11 Apr 2025

    Pixie 1.04 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by admin/modules/static.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3801

    Last Modified: 11 Apr 2025

    SimpleTest 1.0.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by test/visual_test.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3809

    Last Modified: 11 Apr 2025

    TheHostingTool (THT) 1.2.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by includes/pear/Mail/smtp.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3817

    Last Modified: 11 Apr 2025

    Website Baker 2.8.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by admin/media/parameters.php and certain other files. NOTE: this might overlap CVE-2005-2436.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3825

    Last Modified: 11 Apr 2025

    Zend Framework 1.11.3 in Zend Server CE 5.1.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by Validate.php and certain other files.

    Published: 24 Sept 2011
    5
    Medium

    CVE-2011-3695

    Last Modified: 11 Apr 2025

    111WebCalendar 1.2.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by footer.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3696

    Last Modified: 11 Apr 2025

    60cycleCMS 2.5.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by post.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3697

    Last Modified: 11 Apr 2025

    Achievo 1.4.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/graph/jpgraph/jpgraph_radar.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3699

    Last Modified: 11 Apr 2025

    John Lim ADOdb Library for PHP 5.11 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by tests/test-active-record.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3700

    Last Modified: 11 Apr 2025

    Advanced Electron Forum (AEF) 1.0.8 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by languages/english/deletetopic_lang.php.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3701

    Last Modified: 11 Apr 2025

    AlegroCart 1.2.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by common.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3702

    Last Modified: 11 Apr 2025

    Ananta Gazelle 1.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/template.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3703

    Last Modified: 11 Apr 2025

    AneCMS 1.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by widgets/menu/index.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3704

    Last Modified: 11 Apr 2025

    appRain 0.1.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by cron.php.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3705

    Last Modified: 11 Apr 2025

    Arctic Fox CMS 0.9.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by acp/includes/edit.inc.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3709

    Last Modified: 11 Apr 2025

    b2evolution 3.3.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by locales/ru_RU/ru-RU.locale.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3710

    Last Modified: 11 Apr 2025

    bbPress 1.0.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by bb-templates/kakumei/view.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3711

    Last Modified: 11 Apr 2025

    BIGACE 2.7.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by system/libs/javascript.inc.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3712

    Last Modified: 11 Apr 2025

    CakePHP 1.3.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by dispatcher.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3713

    Last Modified: 11 Apr 2025

    cFTP r80 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by templates/session_check.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3716

    Last Modified: 11 Apr 2025

    Claroline 1.9.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by work/connector/linker.cnr.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3720

    Last Modified: 11 Apr 2025

    conceptcms 5.3.1, 5.3.3, and possibly other versions allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by sys_libs/umlib/um_authserver.inc.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3723

    Last Modified: 11 Apr 2025

    Crafty Syntax 3.0.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by README_FILES/livehelp.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3724

    Last Modified: 11 Apr 2025

    CubeCart 4.4.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/shipping/USPS/calc.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3725

    Last Modified: 11 Apr 2025

    DeluxeBB 1.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by header_html.php.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3726

    Last Modified: 11 Apr 2025

    DoceboLMS 4.0.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by views/dummy/show.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3727

    Last Modified: 11 Apr 2025

    DokuWiki 2009-12-25c allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by lib/tpl/index.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3728

    Last Modified: 11 Apr 2025

    Dolphin 7.0.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by xmlrpc/BxDolXMLRPCProfileView.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3730

    Last Modified: 11 Apr 2025

    Drupal 7.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/simpletest/tests/upgrade/drupal-6.upload.database.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3731

    Last Modified: 11 Apr 2025

    e107 0.7.24 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by e107_plugins/pdf/e107pdf.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3732

    Last Modified: 11 Apr 2025

    eggBlog 4.1.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by _lib/fckeditor/editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellchecker.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3733

    Last Modified: 11 Apr 2025

    Elgg 1.7.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by vendors/simpletest/test/visual_test.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3734

    Last Modified: 11 Apr 2025

    Energine 2.3.8 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by core/framework/SimpleBuilder.class.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3735

    Last Modified: 11 Apr 2025

    Escort Agency CMS (aka escort-agency-cms) allows remote attackers to obtain sensitive information via crafted array parameters in a request to a .php file, which reveals the installation path in an error message, as demonstrated by makethumb.php and certain other files.

    Published: 23 Sept 2011