Skip to main content

CWE archive

CWE-200 CVEs

Programmatic archive

10,661 CVEs tagged with CWE-200366 Critical, 2,099 High, 6,992 Medium, 1,199 Low, 5 Unrated.

CVE-2006-6886

Published Dec 31, 2006

phpwcms 1.2.5-DEV allows remote attackers to obtain sensitive information via a direct request for (1) files.public-userroot.inc.php or (2) files.private.additions.inc.php in incl…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6735

Published Dec 26, 2006

modules/viewcategory.php in Minh Nguyen Duong Obie Website Mini Web Shop 2.1.c allows remote attackers to obtain sensitive information via a request with an arbitrary catname para…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6637

Published Dec 19, 2006

The Servlet Engine and Web Container in IBM WebSphere Application Server (WAS) before 6.0.2.17, when ibm-web-ext.xmi sets fileServingEnabled to true and servlet caching is enabled…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6457

Published Dec 11, 2006

tiki-wiki_rss.php in Tikiwiki 1.9.5, 1.9.2, and possibly other versions allows remote attackers to obtain sensitive information (MySQL username and password) via an invalid (large…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5702

Published Nov 4, 2006

Tikiwiki 1.9.5 allows remote attackers to obtain sensitive information (MySQL username and password) via an empty sort_mode parameter in (1) tiki-listpages.php, (2) tiki-lastchang…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5725

Published Nov 4, 2006

The SSL server in AEP Smartgate 4.3b allows remote attackers to determine existence of directories via a direct request for a directory URI, which returns different HTTP status co…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5229

Published Oct 10, 2006

OpenSSH portable 4.1 on SUSE Linux, and possibly other platforms and versions, and possibly under limited configurations, allows remote attackers to determine valid usernames via…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-4595

Published Sep 7, 2006

muforum (µforum) 0.4c stores membres/members.dat under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4537

Published Sep 5, 2006

NET$SESSION_CONTROL.EXE in DECnet-Plus in OpenVMS ALPHA 7.3-2 and Alpha 8.2 writes a password to an audit log file when there is a successful connection after a "network breakin"…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-4223

Published Aug 18, 2006

IBM WebSphere Application Server (WAS) before 6.0.2.13 allows context-dependent attackers to obtain sensitive information via unspecified vectors related to "JSP source code expos…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4136

Published Aug 14, 2006

Multiple unspecified vulnerabilities in IBM WebSphere Application Server before 6.1.0.1 have unspecified impact and attack vectors involving (1) "SOAP requests and responses", (2)…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4006

Published Aug 7, 2006

The do_gameinfo function in BomberClone 0.11.6 and earlier, and possibly other functions, does not reset the packet data size, which causes the send_pkg function (packets.c) to us…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3561

Published Jul 13, 2006

BT Voyager 2091 Wireless firmware 2.21.05.08m_A2pB018c1.d16d and earlier, and 3.01m and earlier, allow remote attackers to bypass the authentication process and gain sensitive inf…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3365

Published Jul 6, 2006

V3 Chat allows remote attackers to obtain the installation path via (1) an invalid id parameter to mail/index.php or (2) membername parameter to messenger/online.php, which displa…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-2384

Published Jun 13, 2006

Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to conduct spoofing and phishing attacks by using a modal browser window in a way that preserves…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-2950

Published Jun 12, 2006

Net Portal Dynamic System (NPDS) 5.10 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) header.php, (2) contact.php, or (3) forum_ext…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-2535

Published May 22, 2006

index.php in Destiney Links Script 2.1.2 allows remote attackers to obtain the installation path via an invalid show parameter referencing a non-existent file, which reveals the p…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-2356

Published May 15, 2006

NmConsole/utility/RenderMap.asp in Ipswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allows remote attackers to obtain sensitive information about network n…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1439

Published May 12, 2006

NSSecureTextField in AppKit in Apple Mac OS X 10.4.6 does not re-enable secure event input under certain circumstances, which could allow other applications in the window session…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-2111

Published May 1, 2006

A component in Microsoft Outlook Express 6 allows remote attackers to bypass domain restrictions and obtain sensitive information via redirections with the mhtml: URI handler, as…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1677

Published Apr 11, 2006

MAXdev MDPro 1.0.73 and 1.0.72, and possibly other versions before 1.076, allows remote attackers to obtain the full path of the server via a direct request to includes/legacy.php.

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 10,551-10,575 of 10,661 CVEsPage 423 of 427