← Back
CWE-200

10,881 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,881)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wordpress
1Wordpress
Apr 23, 2026
Jan 10, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
WordPress 2.2.x and 2.3.x allows remote attackers to obtain sensitive information via an invalid p parameter in an rss2 action to the default URI, which reveals the full path and the SQL database structure.
1Layton Technology
1Helpbox
Apr 23, 2026
Jan 9, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Layton HelpBox 3.7.1 generates different responses depending on whether or not a username is valid in a failed login attempt, which allows remote attackers to enumerate valid usernames.
1Snitz Communications
1Snitz Forums 2000
Apr 23, 2026
Jan 8, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Snitz Forums 2000 3.4.05 allows remote attackers to obtain sensitive information via a direct request to forum/whereami.asp, which reveals the database path.
12z Project
12z Project
Apr 23, 2026
Jan 4, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
2z project 0.9.6.1 allows remote attackers to obtain sensitive information via (1) a request to index.php with an invalid template or (2) a request to the default URI with certain year and month parameters, which reveals...Show more
2z project 0.9.6.1 allows remote attackers to obtain sensitive information via (1) a request to index.php with an invalid template or (2) a request to the default URI with certain year and month parameters, which reveals the path in various error messages.Show less
1Openbiblio
1Openbiblio
Apr 23, 2026
Dec 31, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
OpenBiblio 0.5.2-pre4 and earlier allows remote attackers to obtain sensitive information via a direct request for (1) shared/footer.php, (2) circ/mbr_fields.php, or (3) admin/custom_marc_form_fields.php, which reveals t...Show more
OpenBiblio 0.5.2-pre4 and earlier allows remote attackers to obtain sensitive information via a direct request for (1) shared/footer.php, (2) circ/mbr_fields.php, or (3) admin/custom_marc_form_fields.php, which reveals the path in various error messages.Show less
1Openbiblio
1Openbiblio
Apr 23, 2026
Dec 31, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
OpenBiblio 0.5.2-pre4 and earlier allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function.
1Google
1Toolbar
Apr 23, 2026
Dec 27, 2007
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The Custom Button Installer dialog in Google Toolbar 4 and 5 beta presents certain domain names in the (1) "Downloaded from" and (2) "Privacy considerations" sections without verifying domain names, which makes it easier...Show more
The Custom Button Installer dialog in Google Toolbar 4 and 5 beta presents certain domain names in the (1) "Downloaded from" and (2) "Privacy considerations" sections without verifying domain names, which makes it easier for remote attackers to spoof domain names and trick users into installing malicious button XML files, as demonstrated by presenting www.google.com when the button was downloaded from an arbitrary site through an open redirector on www.google.com.Show less
1Opera
1Opera Browser
Apr 23, 2026
Dec 24, 2007
N/A· v4
N/A· v3
7.8 HIGH· v2
Opera before 9.25 allows remote attackers to obtain potentially sensitive memory contents via a crafted bitmap (BMP) file, as demonstrated using a CANVAS element and JavaScript in an HTML document for copying these conte...Show more
Opera before 9.25 allows remote attackers to obtain potentially sensitive memory contents via a crafted bitmap (BMP) file, as demonstrated using a CANVAS element and JavaScript in an HTML document for copying these contents from 9.50 beta, a related issue to CVE-2008-0420.Show less
1Apache
1Http Server
Apr 23, 2026
Dec 21, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Apache HTTP Server, when running on Linux with a document root on a Windows share mounted using smbfs, allows remote attackers to obtain unprocessed content such as source files for .php programs via a trailing "\" (back...Show more
Apache HTTP Server, when running on Linux with a document root on a Windows share mounted using smbfs, allows remote attackers to obtain unprocessed content such as source files for .php programs via a trailing "\" (backslash), which is not handled by the intended AddType directive.Show less
1Hp
1Esupportdiagnostics
Apr 23, 2026
Dec 21, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
HP eSupportDiagnostics ActiveX control (hpediag.dll) 1.0.11.0 exports dangerous methods, which allows remote attackers to (1) read arbitrary files via the ReadTextFile method, or (2) read arbitrary registry values via th...Show more
HP eSupportDiagnostics ActiveX control (hpediag.dll) 1.0.11.0 exports dangerous methods, which allows remote attackers to (1) read arbitrary files via the ReadTextFile method, or (2) read arbitrary registry values via the ReadValue method.Show less
1Php
1Mysql Banner Exchange
Apr 23, 2026
Dec 21, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
PHP MySQL Banner Exchange 2.2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database information via a direct request to inc/lib.inc.
1Hosting Controller
1Hosting Controller
Apr 23, 2026
Dec 20, 2007
N/A· v4
N/A· v3
5.5 MEDIUM· v2
Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to obtain sensitive information via (1) the AdminName and AdminLevel parameters to fp2000/NEWSRVR.asp, which discloses usernames; and (2) c...Show more
Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to obtain sensitive information via (1) the AdminName and AdminLevel parameters to fp2000/NEWSRVR.asp, which discloses usernames; and (2) certain XML HTTP requests to hosting/css.asp using Microsoft.XMLHTTP or MSXML2.XMLHTTP objects, which trigger a response with the setup directory pathname in the HTML source; and (3) might allow remote attackers to obtain sensitive information via a request for /admin/forum/, which reveals the path in an error message when a forum is not found.Show less
1Gf 3xplorer
1Gf 3xplorer
Apr 23, 2026
Dec 20, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
GF-3XPLORER 2.4 allows remote attackers to obtain configuration information via a direct request to explorer/phpinfo.php, which calls the phpinfo function.
4Centos
FedoraprojectOracle+1 more
9Centos
Enterprise LinuxEnterprise Linux Desktop+6 more
Apr 23, 2026
Dec 18, 2007
N/A· v4
N/A· v3
4.9 MEDIUM· v2
Red Hat Enterprise Linux 5 and Fedora install the Bind /etc/rndc.key file with world-readable permissions, which allows local users to perform unauthorized named commands, such as causing a denial of service by stopping...Show more
Red Hat Enterprise Linux 5 and Fedora install the Bind /etc/rndc.key file with world-readable permissions, which allows local users to perform unauthorized named commands, such as causing a denial of service by stopping named.Show less
1Debian
1Debian Linux
Apr 23, 2026
Dec 18, 2007
N/A· v4
N/A· v3
2.1 LOW· v2
The libdspam7-drv-mysql cron job in Debian GNU/Linux includes the MySQL dspam database password in a command line argument, which might allow local users to read the password by listing the process and its arguments.
1Linux
1Linux Kernel
Apr 23, 2026
Dec 18, 2007
N/A· v4
N/A· v3
7.2 HIGH· v2
The shmem_getpage function (mm/shmem.c) in Linux kernel 2.6.11 through 2.6.23 does not properly clear allocated memory in some rare circumstances related to tmpfs, which might allow local users to read sensitive kernel d...Show more
The shmem_getpage function (mm/shmem.c) in Linux kernel 2.6.11 through 2.6.23 does not properly clear allocated memory in some rare circumstances related to tmpfs, which might allow local users to read sensitive kernel data or cause a denial of service (crash).Show less
1Ibm
1Tivoli Provisioning Manager Express
Apr 23, 2026
Dec 17, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
IBM Tivoli Provisioning Manager Express provides unspecified information in error messages when (1) attempted duplication of a username occurs when creating an account or (2) when trying to login using a valid username,...Show more
IBM Tivoli Provisioning Manager Express provides unspecified information in error messages when (1) attempted duplication of a username occurs when creating an account or (2) when trying to login using a valid username, which makes it easier for remote attackers to enumerate usernames.Show less
1Shttpd
1Shttpd
Apr 23, 2026
Dec 17, 2007
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Sergey Lyubka Simple HTTPD (shttpd) 1.38 and earlier on Windows allows remote attackers to download arbitrary CGI programs or scripts via a URI with an appended (1) '+' character, (2) '.' character, (3) %2e sequence (hex...Show more
Sergey Lyubka Simple HTTPD (shttpd) 1.38 and earlier on Windows allows remote attackers to download arbitrary CGI programs or scripts via a URI with an appended (1) '+' character, (2) '.' character, (3) %2e sequence (hex-encoded dot), or (4) hex-encoded character greater than 0x7f. NOTE: the %20 vector is already covered by CVE-2007-3407.Show less
1Gentoo
1Portage
Apr 23, 2026
Dec 15, 2007
N/A· v4
N/A· v3
2.1 LOW· v2
etc-update in Portage before 2.1.3.11 on Gentoo Linux relies on the umask to set permissions for the merge file, often resulting in permissions weaker than those of the original files, which might allow local users to ob...Show more
etc-update in Portage before 2.1.3.11 on Gentoo Linux relies on the umask to set permissions for the merge file, often resulting in permissions weaker than those of the original files, which might allow local users to obtain sensitive information by reading the merge file.Show less
1Tumusika Evolution
1Tumusika Evolution
Apr 23, 2026
Dec 4, 2007
N/A· v4
N/A· v3
7.8 HIGH· v2
TuMusika Evolution 1.7R5 allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function. NOTE: the provenance of this information is unknown; the detail...Show more
TuMusika Evolution 1.7R5 allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less