← Back
CWE-425

235 CVEs • Abstraction: Base

Direct Request ('Forced Browsing')

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

JSON object

Loading...

CVEs (235)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Frogman Office Inc
2Cs Cart Japanese Edition
Cs Cart Multivendor Japanese Edition
May 13, 2026
Apr 28, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
CS-Cart Japanese Edition v4.3.10-jp-1 and earlier, CS-Cart Multivendor Japanese Edition v4.3.10-jp-1 and earlier allows remote attackers to bypass access restriction to create a request to return a customer purchased ite...Show more
CS-Cart Japanese Edition v4.3.10-jp-1 and earlier, CS-Cart Multivendor Japanese Edition v4.3.10-jp-1 and earlier allows remote attackers to bypass access restriction to create a request to return a customer purchased item via rma.post.php.Show less
1Frogman Office Inc
1Cs Cart
May 13, 2026
Apr 28, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese Edition v4.3.10 and earlier (excluding v2 and v3) allows remote attackers to bypass access restriction to obtain customer i...Show more
CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese Edition v4.3.10 and earlier (excluding v2 and v3) allows remote attackers to bypass access restriction to obtain customer information via orders.pre.php.Show less
1Apple
2Iphone Os
Safari
May 13, 2026
Apr 2, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to spoof the address bar via a crafted...Show more
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to spoof the address bar via a crafted web site.Show less
1Trendmicro
1Deep Discovery Inspector
May 6, 2026
Aug 23, 2015
N/A· v4
N/A· v3
5.5 MEDIUM· v2
Trend Micro Deep Discovery Inspector (DDI) on Deep Discovery Threat appliances with software before 3.5.1477, 3.6.x before 3.6.1217, 3.7.x before 3.7.1248, 3.8.x before 3.8.1263, and other versions allows remote attacker...Show more
Trend Micro Deep Discovery Inspector (DDI) on Deep Discovery Threat appliances with software before 3.5.1477, 3.6.x before 3.6.1217, 3.7.x before 3.7.1248, 3.8.x before 3.8.1263, and other versions allows remote attackers to obtain sensitive information or change the configuration via a direct request to the (1) system log URL, (2) whitelist URL, or (3) blacklist URL.Show less
1Flatnuke
1Flatnuke
Apr 16, 2026
Jun 9, 2005
N/A· v4
N/A· v3
6.4 MEDIUM· v2
FlatNuke 2.5.3 allows remote attackers to cause a denial of service or obtain sensitive information via (1) a direct request to foot_news.php, which triggers an infinite loop, or (2) direct requests to unknown scripts, w...Show more
FlatNuke 2.5.3 allows remote attackers to cause a denial of service or obtain sensitive information via (1) a direct request to foot_news.php, which triggers an infinite loop, or (2) direct requests to unknown scripts, which reveals the web document root in an error message.Show less
1Dlink
1Dsl 504t Firmware
Apr 16, 2026
May 26, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
D-Link DSL-504T allows remote attackers to bypass authentication and gain privileges, such as upgrade firmware, restart the router or restore a saved configuration, via a direct request to firmwarecfg.
1Postnuke
1Postnuke
Apr 16, 2026
May 24, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
PostNuke 0.750 and 0.760RC3 allows remote attackers to obtain sensitive information via a direct request to (1) theme.php or (2) Xanthia.php in the Xanthia module, (3) user.php, (4) thelang.php, (5) text.php, (6) html.ph...Show more
PostNuke 0.750 and 0.760RC3 allows remote attackers to obtain sensitive information via a direct request to (1) theme.php or (2) Xanthia.php in the Xanthia module, (3) user.php, (4) thelang.php, (5) text.php, (6) html.php, (7) menu.php, (8) finclude.php, or (9) button.php in the pnblocks directory in the Blocks module, (10) config.php in the NS-Multisites (aka Multisites) module, or (11) xmlrpc.php, which reveals the path in an error message.Show less
1Postnuke
1Postnuke
Apr 16, 2026
May 24, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The RSS module in PostNuke 0.750 and 0.760RC2 and RC3 allows remote attackers to obtain sensitive information via a direct request to simple_smarty.php, which reveals the path in an error message.
1Wordpress
1Wordpress
Apr 16, 2026
May 20, 2005
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Wordpress 1.5 and earlier allows remote attackers to obtain sensitive information via a direct request to files in (1) wp-content/themes/, (2) wp-includes/, or (3) wp-admin/, which reveal the path in an error message.
1Episodex
1Episodex Guestbook
Apr 16, 2026
May 20, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
episodex guestbook allows remote attackers to bypass authentication and edit scripts via a direct request to admin.asp.
1Yusasp
1Web Asset Manager
Apr 16, 2026
May 18, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
YusASP Web Asset Manager 1.0 allows remote attackers to gain privileges via a direct request to assetmanager.asp.
1Hostingcontroller
1Hosting Controller
Apr 16, 2026
May 18, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
Hosting Controller 6.1 Hotfix 1.9 and earlier allows remote attackers to register arbitrary users via a direct request to addsubsite.asp with the loginname and password parameters set.
1Phpmyfaq
1Phpmyfaq
Apr 16, 2026
Dec 31, 2004
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
phpMyFAQ 1.4.0 allows remote attackers to access the Image Manager to upload or delete images without authorization via a direct request.
1Baalsystems
1Baal Smart Forms
Apr 16, 2026
Dec 31, 2004
N/A· v4
N/A· v3
7.5 HIGH· v2
Baal Smart Forms before 3.2 allows remote attackers to bypass authentication and obtain system access via a direct request to regadmin.php.
1Midicart
3Midicart Php
Midicart Php MaxiMidicart Php Plus
Apr 16, 2026
Dec 31, 2002
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
MidiCart PHP, PHP Plus, and PHP Maxi allows remote attackers to (1) upload arbitrary php files via a direct request to admin/upload.php or (2) access sensitive information via a direct request to admin/credit_card_info.p...Show more
MidiCart PHP, PHP Plus, and PHP Maxi allows remote attackers to (1) upload arbitrary php files via a direct request to admin/upload.php or (2) access sensitive information via a direct request to admin/credit_card_info.php.Show less