Skip to main content

CWE archive

CWE-200 CVEs

Programmatic archive

10,347 CVEs tagged with CWE-200345 Critical, 2,000 High, 6,835 Medium, 1,163 Low, 4 Unrated.

CVE-2007-1167

Published Mar 2, 2007

inc/filebrowser/browser.php in deV!L`z Clanportal (DZCP) 1.4.5 and earlier allows remote attackers to obtain MySQL data via the inc/mysql.php value of the file parameter.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-1194

Published Mar 2, 2007

Norman SandBox Analyzer does not use the proper range for Interrupt Descriptor Table (IDT) entries, which allows local users to determine that the local machine is an emulator, or…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-1116

Published Feb 26, 2007

The CheckLoadURI function in Mozilla Firefox 1.8 lists the about: URI as a ChromeProtocol and can be loaded via JavaScript, which allows remote attackers to obtain sensitive infor…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-1044

Published Feb 21, 2007

Pearson Education PowerSchool 4.3.6 allows remote attackers to list the contents of the admin folder via a URI composed of the admin/ directory name and an arbitrary filename endi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0979

Published Feb 16, 2007

Unspecified vulnerability in LifeType before 1.1.6, and 1.2 before 1.2-beta2, allows remote attackers to obtain sensitive information (file contents) via a "crafted URL."

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6998

Published Feb 12, 2007

install/loader_help.php in Headstart Solutions DeskPRO allows remote attackers to obtain configuration information via a q=phpinfo QUERY_STRING, which calls the phpinfo function.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6999

Published Feb 12, 2007

attachment.php in Headstart Solutions DeskPRO allows remote attackers to read all uploaded files by providing the file number in a modified id parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6953

Published Jan 29, 2007

The virtual keyboard implementation in GlobeTrotter Mobility Manager changes the color of a key as it is pressed, which allows local users to capture arbitrary keystrokes, such as…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-0259

Published Jan 16, 2007

Ezboxx Portal System Beta 0.7.6 and earlier allows remote attackers to obtain sensitive information via an invalid cat parameter to boxx/knowledgebase.asp, which reveals the path…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6886

Published Dec 31, 2006

phpwcms 1.2.5-DEV allows remote attackers to obtain sensitive information via a direct request for (1) files.public-userroot.inc.php or (2) files.private.additions.inc.php in incl…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6735

Published Dec 26, 2006

modules/viewcategory.php in Minh Nguyen Duong Obie Website Mini Web Shop 2.1.c allows remote attackers to obtain sensitive information via a request with an arbitrary catname para…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6637

Published Dec 19, 2006

The Servlet Engine and Web Container in IBM WebSphere Application Server (WAS) before 6.0.2.17, when ibm-web-ext.xmi sets fileServingEnabled to true and servlet caching is enabled…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6457

Published Dec 11, 2006

tiki-wiki_rss.php in Tikiwiki 1.9.5, 1.9.2, and possibly other versions allows remote attackers to obtain sensitive information (MySQL username and password) via an invalid (large…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5702

Published Nov 4, 2006

Tikiwiki 1.9.5 allows remote attackers to obtain sensitive information (MySQL username and password) via an empty sort_mode parameter in (1) tiki-listpages.php, (2) tiki-lastchang…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5725

Published Nov 4, 2006

The SSL server in AEP Smartgate 4.3b allows remote attackers to determine existence of directories via a direct request for a directory URI, which returns different HTTP status co…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5229

Published Oct 10, 2006

OpenSSH portable 4.1 on SUSE Linux, and possibly other platforms and versions, and possibly under limited configurations, allows remote attackers to determine valid usernames via…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-4595

Published Sep 7, 2006

muforum (µforum) 0.4c stores membres/members.dat under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4537

Published Sep 5, 2006

NET$SESSION_CONTROL.EXE in DECnet-Plus in OpenVMS ALPHA 7.3-2 and Alpha 8.2 writes a password to an audit log file when there is a successful connection after a "network breakin"…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-4223

Published Aug 18, 2006

IBM WebSphere Application Server (WAS) before 6.0.2.13 allows context-dependent attackers to obtain sensitive information via unspecified vectors related to "JSP source code expos…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4136

Published Aug 14, 2006

Multiple unspecified vulnerabilities in IBM WebSphere Application Server before 6.1.0.1 have unspecified impact and attack vectors involving (1) "SOAP requests and responses", (2)…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4006

Published Aug 7, 2006

The do_gameinfo function in BomberClone 0.11.6 and earlier, and possibly other functions, does not reset the packet data size, which causes the send_pkg function (packets.c) to us…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3561

Published Jul 13, 2006

BT Voyager 2091 Wireless firmware 2.21.05.08m_A2pB018c1.d16d and earlier, and 3.01m and earlier, allow remote attackers to bypass the authentication process and gain sensitive inf…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 10,226-10,250 of 10,347 CVEsPage 410 of 414