Total
7102 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2011-4852 | 2 Microsoft, Parallels | 3 Windows 2003 Server, Windows Server 2008, Parallels Plesk Panel | 2017-08-29 | 4.3 MEDIUM | N/A |
The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 generates web pages containing external links in response to GET requests with query strings for enterprise/mobile-monitor/ and certain other files, which makes it easier for remote attackers to obtain sensitive information by reading (1) web-server access logs or (2) web-server Referer logs, related to a "cross-domain Referer leakage" issue. | |||||
CVE-2011-4849 | 2 Microsoft, Parallels | 3 Windows 2003 Server, Windows Server 2008, Parallels Plesk Panel | 2017-08-29 | 4.3 MEDIUM | N/A |
The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session, as demonstrated by cookies used by help.php and certain other files. | |||||
CVE-2011-3778 | 1 Phpgedview | 1 Phpgedview | 2017-08-29 | 5.0 MEDIUM | N/A |
PhpGedView 4.2.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by serviceClientTest.php and certain other files. | |||||
CVE-2011-3580 | 1 Icewarp | 1 Mail Server | 2017-08-29 | 5.0 MEDIUM | N/A |
IceWarp WebMail in IceWarp Mail Server before 10.3.3 allows remote attackers to obtain configuration information via a direct request to the /server URI, which triggers a call to the phpinfo function. | |||||
CVE-2011-3762 | 1 Open-blog | 1 Openblog | 2017-08-29 | 5.0 MEDIUM | N/A |
OpenBlog 1.2.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by system/scaffolding/views/view.php and certain other files. | |||||
CVE-2011-3246 | 1 Apple | 3 Iphone Os, Mac Os X, Mac Os X Server | 2017-08-29 | 5.0 MEDIUM | N/A |
CFNetwork in Apple iOS before 5.0.1 and Mac OS X 10.7 before 10.7.2 does not properly parse URLs, which allows remote attackers to trigger visits to unintended web sites, and transmission of cookies to unintended web sites, via a crafted (1) http or (2) https URL. | |||||
CVE-2011-3264 | 1 Zabbix | 1 Zabbix | 2017-08-29 | 5.0 MEDIUM | N/A |
Zabbix before 1.8.6 allows remote attackers to obtain sensitive information via an invalid srcfld2 parameter to popup.php, which reveals the installation path in an error message. | |||||
CVE-2011-3774 | 1 Bishop Bettini | 1 Phpesp | 2017-08-29 | 5.0 MEDIUM | N/A |
php Easy Survey Package (phpESP) 2.1.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by public/landing.php and certain other files. | |||||
CVE-2011-3427 | 1 Apple | 2 Apple Tv, Iphone Os | 2017-08-29 | 2.6 LOW | N/A |
The Data Security component in Apple iOS before 5 and Apple TV before 4.4 does not properly restrict use of the MD5 hash algorithm within X.509 certificates, which makes it easier for man-in-the-middle attackers to spoof servers or obtain sensitive information via a crafted certificate. | |||||
CVE-2011-3761 | 1 Dietrich Ayala | 1 Nusoap | 2017-08-29 | 5.0 MEDIUM | N/A |
NuSOAP 0.9.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by nuSOAP/classes/class.wsdl.php and certain other files. | |||||
CVE-2011-3768 | 1 Phorum | 1 Phorum | 2017-08-29 | 5.0 MEDIUM | N/A |
Phorum 5.2.15a allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by css.php and certain other files. | |||||
CVE-2011-3777 | 1 Phpfreechat | 1 Phpfreechat | 2017-08-29 | 5.0 MEDIUM | N/A |
phpFreeChat 1.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by themes/zilveer/style.css.php and certain other files. | |||||
CVE-2011-3769 | 1 Blondish | 1 Phpads | 2017-08-29 | 5.0 MEDIUM | N/A |
PHPads 2.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by ads.inc.php. | |||||
CVE-2012-0130 | 1 Hp | 1 Onboard Administrator | 2017-08-29 | 5.0 MEDIUM | N/A |
HP Onboard Administrator (OA) before 3.50 allows remote attackers to obtain sensitive information via unspecified vectors. | |||||
CVE-2011-3713 | 1 Powerdrummer | 1 Cftp | 2017-08-29 | 5.0 MEDIUM | N/A |
cFTP r80 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by templates/session_check.php and certain other files. | |||||
CVE-2011-3126 | 1 Wordpress | 1 Wordpress | 2017-08-29 | 5.0 MEDIUM | N/A |
WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 allows remote attackers to determine usernames of non-authors via canonical redirects. | |||||
CVE-2011-3431 | 1 Apple | 1 Iphone Os | 2017-08-29 | 2.1 LOW | N/A |
The Home screen component in Apple iOS before 5 does not properly support a certain application-switching gesture, which might allow physically proximate attackers to obtain sensitive state information by watching the device's screen. | |||||
CVE-2011-3128 | 1 Wordpress | 1 Wordpress | 2017-08-29 | 5.0 MEDIUM | N/A |
WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 treats unattached attachments as published, which might allow remote attackers to obtain sensitive data via vectors related to wp-includes/post.php. | |||||
CVE-2011-4760 | 1 Parallels | 1 Parallels Plesk Small Business Panel | 2017-08-29 | 5.0 MEDIUM | N/A |
Parallels Plesk Small Business Panel 10.2.0 has web pages containing e-mail addresses that are not intended for correspondence about the local application deployment, which allows remote attackers to obtain potentially sensitive information by reading a page, as demonstrated by smb/email-address/list and certain other files. | |||||
CVE-2011-3771 | 1 Gnu | 1 Phpbook | 2017-08-29 | 5.0 MEDIUM | N/A |
phpBook 2.1.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by doc/update_smilies_1.50-1.60.php and certain other files. |