CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2011-3736

    Last Modified: 11 Apr 2025

    ExoPHPDesk 1.2.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by upgrades/upgrade9.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3739

    Last Modified: 11 Apr 2025

    Freeway 1.5 Alpha allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by templates/Freeway/boxes/last_product.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3741

    Last Modified: 11 Apr 2025

    Ganglia 3.1.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by host_view.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3743

    Last Modified: 11 Apr 2025

    Hesk 2.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by inc/footer.inc.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3744

    Last Modified: 11 Apr 2025

    HTML Purifier 4.2.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by tests/PHPT/Reporter/SimpleTest.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3745

    Last Modified: 11 Apr 2025

    HycusCMS 1.0.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by templates/hycus_template/template.php.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3746

    Last Modified: 11 Apr 2025

    Jcow 4.2.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by themes/default/page.tpl.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3747

    Last Modified: 11 Apr 2025

    Joomla! 1.6.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by libraries/phpmailer/language/phpmailer.lang-joomla.php.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3748

    Last Modified: 11 Apr 2025

    Kamads Classifieds 2_B3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by V2A_XHTML/style/view.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3749

    Last Modified: 11 Apr 2025

    ka-Map 1.0-20070205 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by test.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3751

    Last Modified: 11 Apr 2025

    LifeType 1.2.10 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by plugins/badbehavior/pluginbadbehavior.class.php.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3752

    Last Modified: 11 Apr 2025

    LimeSurvey 1.90+ build9642-20101214 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by admin/statistics.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3753

    Last Modified: 11 Apr 2025

    LinPHA 1.3.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by viewer.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3754

    Last Modified: 11 Apr 2025

    Mambo 4.6.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by includes/sef.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3755

    Last Modified: 11 Apr 2025

    MantisBT 1.2.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by view_all_inc.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3756

    Last Modified: 11 Apr 2025

    MicroBlog 0.9.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by init.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3757

    Last Modified: 11 Apr 2025

    Moodle 2.0.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by webservice/xmlrpc/locallib.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3708

    Last Modified: 11 Apr 2025

    Automne 4.0.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by admin/page-redirect-info.php.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3715

    Last Modified: 11 Apr 2025

    ClanTiger 1.1.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by widgets/statistics/statistics.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3718

    Last Modified: 11 Apr 2025

    CMS Made Simple (CMSMS) 1.9.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/TinyMCE/TinyMCE.module.php and certain other files. NOTE: this might overlap CVE-2007-5444.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3721

    Last Modified: 11 Apr 2025

    concrete 5.4.0.5, 5.4.1, and 5.4.1.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by tools/spellchecker_service.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3738

    Last Modified: 11 Apr 2025

    Feng Office 1.7.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by public/upgrade/templates/layout.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3740

    Last Modified: 11 Apr 2025

    FrontAccounting 2.3.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by reporting/includes/fpdi/fpdi2tcpdf_bridge.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3759

    Last Modified: 11 Apr 2025

    MyBB (aka MyBulletinBoard) 1.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by inc/3rdparty/diff/Diff/ThreeWay.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3714

    Last Modified: 11 Apr 2025

    ClanSphere 2010.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by mods/board/attachment.php.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3717

    Last Modified: 11 Apr 2025

    ClipBucket 2.0.9 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by plugins/signup_captcha/signup_captcha.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3719

    Last Modified: 11 Apr 2025

    CodeIgniter 1.7.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by system/scaffolding/views/view.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3698

    Last Modified: 11 Apr 2025

    AdaptCMS 2.0.2 Beta allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by inc/poll_vote.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3706

    Last Modified: 11 Apr 2025

    ATutor 2.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by users/tool_settings.inc.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3707

    Last Modified: 11 Apr 2025

    JanRain PHP OpenID library (aka php-openid) 2.2.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by Auth/Yadis/Yadis.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3722

    Last Modified: 11 Apr 2025

    Coppermine Photo Gallery (CPG) 1.5.12 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by include/inspekt.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3729

    Last Modified: 11 Apr 2025

    dotproject 2.1.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by style/dp-grey-theme/footer.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3737

    Last Modified: 11 Apr 2025

    eyeOS 2.2.0.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by apps/rmail/webmail/program/lib/Net/SMTP.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3742

    Last Modified: 11 Apr 2025

    HelpCenter Live 2.1.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/HelpCenter/index.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3750

    Last Modified: 11 Apr 2025

    kPlaylist 1.8.502 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by getid3/getid3/write.id3v1.php and certain other files.

    Published: 23 Sept 2011
    5
    Medium

    CVE-2011-3758

    Last Modified: 11 Apr 2025

    ::mound:: 2.1.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by lib/smarty/libs/sysplugins/smarty_internal_template.php and certain other files.

    Published: 23 Sept 2011
    7.5
    High

    CVE-2011-2766

    Last Modified: 11 Apr 2025

    The FCGI (aka Fast CGI) module 0.70 through 0.73 for Perl, as used by CGI::Fast, uses environment variable values from one request during processing of a later request, which allows remote attackers to bypass authentication via crafted HTTP headers.

    Published: 23 Sept 2011
    9
    Critical

    CVE-2011-2543

    Last Modified: 11 Apr 2025

    Buffer overflow in the cuil component in Cisco Telepresence System Integrator C Series 4.x before TC4.2.0 allows remote authenticated users to cause a denial of service (endpoint reboot or process crash) or possibly execute arbitrary code via a long location parameter to the getxml program, aka Bug ID CSCtq46496.

    Published: 23 Sept 2011
    3.5
    Low

    CVE-2011-2544

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the web interface in Cisco TelePresence System MXP Series F9.1 and earlier allows remote authenticated users to inject arbitrary web script or HTML via a crafted Call ID, as demonstrated by resultant cross-site request forgery (CSRF) attacks that change passwords or cause a denial of service, aka Bug ID CSCtq46488.

    Published: 23 Sept 2011
    7.1
    High

    CVE-2011-3640

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Mozilla Network Security Services (NSS), as used in Google Chrome before 17 on Windows and Mac OS X, might allow local users to gain privileges via a Trojan horse pkcs11.txt file in a top-level directory. NOTE: the vendor's response was "Strange behavior, but we're not treating this as a security bug."

    Published: 23 Sept 2011
    7.5
    High

    CVE-2011-3379

    Last Modified: 11 Apr 2025

    The is_a function in PHP 5.3.7 and 5.3.8 triggers a call to the __autoload function, which makes it easier for remote attackers to execute arbitrary code by providing a crafted URL and leveraging potentially unsafe behavior in certain PEAR packages and custom autoloaders.

    Published: 23 Sept 2011
    7.5
    High

    CVE-2011-1913

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the login form in the web interface in Mercator SENTINEL 2.0 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 22 Sept 2011
    2.6
    Low

    CVE-2011-3328

    Last Modified: 11 Apr 2025

    The png_handle_cHRM function in pngrutil.c in libpng 1.5.4, when color-correction support is enabled, allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a malformed PNG image containing a cHRM chunk associated with a certain zero value.

    Published: 22 Sept 2011
    10
    Critical

    CVE-2011-2412

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Business Service Automation (BSA) Essentials 2.01 allows remote attackers to execute arbitrary code via unknown vectors.

    Published: 21 Sept 2011
    4.3
    Medium

    CVE-2011-2937

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the UI messages functionality in Roundcube Webmail before 0.5.4 allows remote attackers to inject arbitrary web script or HTML via the _mbox parameter to the default URI.

    Published: 21 Sept 2011
    4.3
    Medium

    CVE-2011-2938

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in filter_api.php in MantisBT before 1.2.7 allow remote attackers to inject arbitrary web script or HTML via a parameter, as demonstrated by the project_id parameter to search.php.

    Published: 21 Sept 2011
    4.3
    Medium

    CVE-2011-3356

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in config_defaults_inc.php in MantisBT before 1.2.8 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO, as demonstrated by the PATH_INFO to (1) manage_config_email_page.php, (2) manage_config_workflow_page.php, or (3) bugs/plugin.php.

    Published: 21 Sept 2011
    6.8
    Medium

    CVE-2011-3357

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in bug_actiongroup_ext_page.php in MantisBT before 1.2.8 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the action parameter, related to bug_actiongroup_page.php.

    Published: 21 Sept 2011
    4.3
    Medium

    CVE-2011-3358

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in MantisBT before 1.2.8 allow remote attackers to inject arbitrary web script or HTML via the (1) os, (2) os_build, or (3) platform parameter to (a) bug_report_page.php or (b) bug_update_advanced_page.php, related to use of the Projax library.

    Published: 21 Sept 2011
    4.3
    Medium

    CVE-2011-3578

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in bug_actiongroup_ext_page.php in MantisBT before 1.2.8 allows remote attackers to inject arbitrary web script or HTML via the action parameter, related to bug_actiongroup_page.php, a different vulnerability than CVE-2011-3357.

    Published: 21 Sept 2011