CWE-538
93 CVEs • Abstraction: Base
Insertion of Sensitive Information into Externally-Accessible File or Directory
The product places sensitive information into files or directories that are accessible to actors who are allowed to have access to the files, but not to the sensitive information.
CVEs (93)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cisco 1Enterprise Network Functions Virtualization Infrastructure Jun 17, 2026 Aug 21, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability in the web server functionality of Cisco Enterprise Network Functions Virtualization Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to perform file enumeration on an affecte...Show more |
cPanel before 70.0.23 exposes Apache HTTP Server logs after creation of certain domains (SEC-406). |
Jenkins Credentials Plugin 2.1.18 and earlier allowed users with permission to create or update credentials to confirm the existence of files on the Jenkins master with an attacker-specified path, and obtain the certific...Show more |
The Apache Thrift Node.js static web server in versions 0.9.2 through 0.11.0 have been determined to contain a security vulnerability in which a remote user has the ability to access files outside the set webservers docr...Show more |
1Wisetail 1Learning Management System Nov 21, 2024 Sep 12, 2018 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Wisetail Learning Ecosystem (LE) through v4.11.6 allows insecure direct object reference (IDOR) attacks to download non-purchased course files via a modified id parameter. |
The existence of a specifically requested local file can be found due to the double firing of the "onerror" when the "source" attribute on a "<track>" tag refers to a file that does not exist if the source page is loaded...Show more |
1Advantech 4Webaccess Webaccess/nmsWebaccess Dashboard+1 moreNov 21, 2024 May 15, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and pri...Show more |
1Siemens 1Simatic Wincc Oa Operator Nov 21, 2024 Apr 23, 2018 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 A vulnerability has been identified in SIMATIC WinCC OA Operator iOS App (All versions < V1.4). Insufficient protection of sensitive information (e.g. session key for accessing server) in Siemens WinCC OA Operator iOS ap...Show more |
1Synology 1Surveillance Station Nov 21, 2024 Feb 27, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 File and directory information exposure vulnerability in SYNO.SurveillanceStation.PersonalSettings.Photo in Synology Surveillance Station before 8.1.2-5469 allows remote authenticated users to obtain other user's sensiti...Show more |
1Siemens 4Apogee Pxc Firmware Apogee Pxc Modular FirmwareTalon Tc Compact Firmware+1 moreJun 2, 2026 Oct 23, 2017 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability has been identified in Siemens APOGEE PXC and TALON TC BACnet Automation Controllers in all versions <V3.5. A directory traversal vulnerability could allow a remote attacker with network access to the int...Show more |
Sendio versions before 8.2.1 were affected by a Local File Inclusion vulnerability that allowed an unauthenticated, remote attacker to read potentially sensitive system files via a specially crafted URL. |
The BWOCXRUN.BwocxrunCtrl.1 control contains a method named OpenUrlToBufferTimeout. This method takes a URL as a parameter and returns its contents to the caller in JavaScript. The URLs are accessed in the security co...Show more |
The BWOCXRUN.BwocxrunCtrl.1 control contains a method named “OpenUrlToBuffer.” This method takes a URL as a parameter and returns its contents to the caller in JavaScript. The URLs are accessed in the security context...Show more |