CWE-200— Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.— MITRE CWE catalog
11,532 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-200page 21 of 231
- CVE-2011-3807MEDIUMCVSS v2 5.0EG 5.02011-09-24
Textpattern 4.2.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by lib/txplib_db.php and certain other files.
- CVE-2011-3808MEDIUMCVSS v2 5.0EG 5.02011-09-24
The Bug Genie 2.1.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/svn_integration/config.inc.php and certain…
- CVE-2011-3809MEDIUMCVSS v2 5.0EG 5.02011-09-24
TheHostingTool (THT) 1.2.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by includes/pear/Mail/smtp.php and certain oth…
- CVE-2011-3810MEDIUMCVSS v2 5.0EG 5.02011-09-24
TinyWebGallery (TWG) 1.8.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by i_frames/i_register.php.
- CVE-2011-3811MEDIUMCVSS v2 5.0EG 5.02011-09-24
TomatoCart 1.1.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by templates/system/offline.php and certain other files.
- CVE-2011-3812MEDIUMCVSS v2 5.0EG 5.02011-09-24
Vanilla 2.0.16 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by plugins/Minify/min/utils.php and certain other files.
- CVE-2011-3813MEDIUMCVSS v2 5.0EG 5.02011-09-24
Virtual War (aka VWar) 1.5.0r15 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by includes/language/dutch.inc.php and ce…
- CVE-2011-3814MEDIUMCVSS v2 5.0EG 5.02011-09-24
WebCalendar 1.2.3, and other versions before 1.2.5, allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by ws/user_mod.php an…
- CVE-2011-3815MEDIUMCVSS v2 5.0EG 5.02011-09-24
WeBid 1.0.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by js/calendar.php and certain other files.
- CVE-2011-3816MEDIUMCVSS v2 5.0EG 5.02011-09-24
WEBinsta mailing list manager 1.3e allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by install/install3.php and certain ot…
- CVE-2011-3817MEDIUMCVSS v2 5.0EG 5.02011-09-24
Website Baker 2.8.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by admin/media/parameters.php and certain other files…
- CVE-2011-3818MEDIUMCVSS v2 5.0EG 5.02011-09-24
WordPress 2.9.2 and 3.0.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by wp-admin/includes/user.php and certain other…
- CVE-2011-3819MEDIUMCVSS v2 5.0EG 5.02011-09-24
WoW Server Status 4.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by status.php and certain other files.
- CVE-2011-3820MEDIUMCVSS v2 5.0EG 5.02011-09-24
WSN Software 6.0.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by includes/prestart.php and certain other files.
- CVE-2011-3821MEDIUMCVSS v2 5.0EG 5.02011-09-24
xajax 0.6 beta1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by xajax_core/plugin_layer/xajaxScriptPlugin.inc.php and …
- CVE-2011-3822MEDIUMCVSS v2 5.0EG 5.02011-09-24
XOOPS 2.5.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/system/xoops_version.php and certain other files.
- CVE-2011-3823MEDIUMCVSS v2 5.0EG 5.02011-09-24
Yamamah 1.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by themes/default/index.php and certain other files.
- CVE-2011-3824MEDIUMCVSS v2 5.0EG 5.02011-09-24
Your Own URL Shortener (YOURLS) 1.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by includes/auth.php and certain othe…
- CVE-2011-3825MEDIUMCVSS v2 5.0EG 5.02011-09-24
Zend Framework 1.11.3 in Zend Server CE 5.1.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by Validate.php and certain…
- CVE-2011-3826MEDIUMCVSS v2 5.0EG 5.02011-09-24
Zikula 1.2.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by themes/voodoodolly/version.php and certain other files.
- CVE-2011-3829MEDIUMCVSS v2 4.0EG 4.02012-01-29
ftp_upload_file.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated users to obtain sensitive information via the file name, which reveals the installation path in an error message.
- CVE-2011-3901HIGHCVSS 7.5EG 7.52020-02-12
Android SQLite Journal before 4.0.1 has an information disclosure vulnerability.
- CVE-2011-3975LOWCVSS v2 2.6EG 2.62011-10-03
A certain HTC update for Android 2.3.4 build GRJ22, when the Sense interface is used on the HTC EVO 3D, EVO 4G, ThunderBolt, and unspecified other devices, provides the HtcLoggers.apk application, which allows user-assisted remote attacker…
- CVE-2011-4014MEDIUMCVSS v2 4.0EG 4.02012-05-02
The TAC Case Attachment tool in Cisco Wireless Control System (WCS) 7.0 allows remote authenticated users to read arbitrary files under webnms/Temp/ via unspecified vectors, aka Bug ID CSCtq86807.
- CVE-2011-4076MEDIUMCVSS 5.9EG 5.92019-11-26
OpenStack Nova before 2012.1 allows someone with access to an EC2_ACCESS_KEY (equivalent to a username) to obtain the EC2_SECRET_KEY (equivalent to a password). Exposing the EC2_ACCESS_KEY via http or tools that allow man-in-the-middle ove…
- CVE-2011-4088HIGHCVSS 7.5EG 7.52020-01-31
ABRT might allow attackers to obtain sensitive information from crash reports.
- CVE-2011-4129MEDIUMCVSS v2 5.8EG 5.82012-10-22
(1) services/twitter/twitter-contact-view.c and (2) services/twitter/twitter-item-view.c in libsocialweb before 0.25.20 automatically connect to Twitter when no Twitter account is set, which might allow remote attackers to obtain sensitive…
- CVE-2011-4143MEDIUMCVSS v2 5.0EG 5.02012-01-27
EMC RSA enVision 4.0 before SP4 P5 and 4.1 before P3 allows remote attackers to obtain sensitive information about environment variables in the web system via unspecified vectors.
- CVE-2011-4232MEDIUMCVSS v2 5.0EG 5.02012-05-03
The web server in Cisco Unified MeetingPlace 6.1 and 8.5 produces different responses for directory queries depending on whether the directory exists, which allows remote attackers to enumerate directory names via a series of queries, aka …
- CVE-2011-4276MEDIUMCVSS v2 4.3EG 4.32012-01-25
The Bluetooth service (com/android/phone/BluetoothHeadsetService.java) in Android 2.3 before 2.3.6 allows remote attackers within Bluetooth range to obtain contact data via an AT phonebook transfer.
- CVE-2011-4304MEDIUMCVSS v2 4.0EG 4.02012-07-11
The chat functionality in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote authenticated users to discover the name of any user via a beep operation.
- CVE-2011-4327MEDIUMCVSS 5.5EG 5.52014-02-03
ssh-keysign.c in ssh-keysign in OpenSSH before 5.8p2 on certain platforms executes ssh-rand-helper with unintended open file descriptors, which allows local users to obtain sensitive key information via the ptrace system call.
- CVE-2011-4343HIGHCVSS 7.5EG 7.52017-08-08
Information disclosure vulnerability in Apache MyFaces Core 2.0.1 through 2.0.10 and 2.1.0 through 2.1.4 allows remote attackers to inject EL expressions via crafted parameters.
- CVE-2011-4360MEDIUMCVSS v2 5.0EG 5.02012-01-08
MediaWiki before 1.17.1 allows remote attackers to obtain the page titles of all restricted pages via a series of requests involving the (1) curid or (2) oldid parameter.
- CVE-2011-4497LOWCVSS v2 3.3EG 3.32011-11-21
QIS_wizard.htm on the ASUS RT-N56U router with firmware before 1.0.1.4o allows remote attackers to obtain the administrator password via a flag=detect request.
- CVE-2011-4538MEDIUMCVSS 5.3EG 5.32020-03-09
Lexmark X, W, T, E, and C devices before 2012-02-09 allow attackers to obtain sensitive information by reading passwords within exported settings.
- CVE-2011-4581MEDIUMCVSS v2 4.0EG 4.02012-07-20
mod/wiki/pagelib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 allows remote authenticated users to discover the username of a wiki creator by visiting the history and deletion user interface.
- CVE-2011-4593MEDIUMCVSS v2 4.0EG 4.02012-07-20
Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle user/action_redir group messages, which allows remote authenticated users to discover e-mail addresses by visiting the messaging interface.
- CVE-2011-4597MEDIUMCVSS v2 5.0EG 5.02011-12-15
The SIP over UDP implementation in Asterisk Open Source 1.4.x before 1.4.43, 1.6.x before 1.6.2.21, and 1.8.x before 1.8.7.2 uses different port numbers for responses to invalid requests depending on whether a SIP username exists, which al…
- CVE-2011-4598MEDIUMCVSS v2 4.3EG 4.32011-12-15
The handle_request_info function in channels/chan_sip.c in Asterisk Open Source 1.6.2.x before 1.6.2.21 and 1.8.x before 1.8.7.2, when automon is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and d…
- CVE-2011-4627MEDIUMCVSS 6.5EG 6.52019-11-06
TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows Information Disclosure on the backend.
- CVE-2011-4697MEDIUMCVSS v2 6.4EG 6.42012-01-25
The Xiaomi MiTalk Messenger (com.xiaomi.channel) application before 2.1.320 for Android does not properly protect data, which allows remote attackers to read or modify messaging information via a crafted application.
- CVE-2011-4698MEDIUMCVSS v2 6.4EG 6.42012-01-25
The AndroidAppTools Easy Filter (com.phoneblocker.android) application 1.1 and 1.2 for Android does not properly protect data, which allows remote attackers to read or modify SMS messages and call records via a crafted application.
- CVE-2011-4699MEDIUMCVSS v2 6.4EG 6.42012-01-25
The Ubermedia Twidroyd Legacy (com.twidroydlegacy) application 4.3.11 for Android does not properly protect data, which allows remote attackers to read or modify Twitter information via a crafted application.
- CVE-2011-4728MEDIUMCVSS v2 5.0EG 5.02011-12-16
The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmi…
- CVE-2011-4731MEDIUMCVSS v2 5.0EG 5.02011-12-16
The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 includes an RFC 1918 IP address within a web page, which allows remote attackers to obtain potentially sensitive information by reading this page, as demons…
- CVE-2011-4737MEDIUMCVSS v2 5.0EG 5.02011-12-16
The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 includes a submitted password within an HTTP response body, which allows remote attackers to obtain sensitive information by sniffing the network, as demonstrated by passw…
- CVE-2011-4738MEDIUMCVSS v2 5.0EG 5.02011-12-16
The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 does not include the HTTPOnly flag in a Set-Cookie header for a cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script a…
- CVE-2011-4740MEDIUMCVSS v2 4.3EG 4.32011-12-16
The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 generates web pages containing external links in response to GET requests with query strings for smb/app/search-data/catalogId/marketplace and certain other files, which m…
- CVE-2011-4741MEDIUMCVSS v2 5.0EG 5.02011-12-16
The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 includes a database connection string within a web page, which allows remote attackers to obtain potentially sensitive information by reading this page, as demonstrated by…
Map vulnerabilities like CWE-200 to your infrastructure
EchelonGraph correlates every CVE — across CWE-200 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →