CWE-200— Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.— MITRE CWE catalog
11,177 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-200page 3 of 224
- CVE-2006-1677MEDIUMCVSS v2 6.4EG 6.42006-04-11
MAXdev MDPro 1.0.73 and 1.0.72, and possibly other versions before 1.076, allows remote attackers to obtain the full path of the server via a direct request to includes/legacy.php.
- CVE-2006-2111MEDIUMCVSS v2 4.3EG 4.32006-05-01
A component in Microsoft Outlook Express 6 allows remote attackers to bypass domain restrictions and obtain sensitive information via redirections with the mhtml: URI handler, as originally reported for Internet Explorer 6 and 7, aka "URL …
- CVE-2006-2341MEDIUMCVSS v2 5.0EG 5.02006-05-12
The HTTP proxy in Symantec Gateway Security 5000 Series 2.0.1 and 3.0, and Enterprise Firewall 8.0, when NAT is being used, allows remote attackers to determine internal IP addresses by using malformed HTTP requests, as demonstrated using …
- CVE-2006-2356MEDIUMCVSS v2 5.0EG 5.02006-05-15
NmConsole/utility/RenderMap.asp in Ipswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allows remote attackers to obtain sensitive information about network nodes via a modified nDeviceGroupID parameter.
- CVE-2006-2384MEDIUMCVSS v2 4.3EG 4.32006-06-13
Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to conduct spoofing and phishing attacks by using a modal browser window in a way that preserves the original address bar and trusted UI of a trusted site, …
- CVE-2006-2535MEDIUMCVSS v2 5.0EG 5.02006-05-22
index.php in Destiney Links Script 2.1.2 allows remote attackers to obtain the installation path via an invalid show parameter referencing a non-existent file, which reveals the path in the resulting error message. NOTE: this issue might …
- CVE-2006-2613MEDIUMCVSS v2 4.3EG 4.32006-05-26
Mozilla Suite 1.7.13, Mozilla Firefox 1.5.0.3 and possibly other versions before before 1.8.0, and Netscape 7.2 and 8.1, and possibly other versions and products, allows remote user-assisted attackers to obtain information such as the inst…
- CVE-2006-2900MEDIUMCVSS v2 4.0EG 4.02006-06-07
Internet Explorer 6 allows user-assisted remote attackers to read arbitrary files by tricking a user into typing the characters of the target filename in a text box and using the OnKeyDown, OnKeyPress, and OnKeyUp Javascript keystroke even…
- CVE-2006-2950MEDIUMCVSS v2 5.0EG 5.02006-06-12
Net Portal Dynamic System (NPDS) 5.10 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) header.php, (2) contact.php, or (3) forum_extender.php, which reveals the path in an error message.
- CVE-2006-3365LOWCVSS v2 2.6EG 2.62006-07-06
V3 Chat allows remote attackers to obtain the installation path via (1) an invalid id parameter to mail/index.php or (2) membername parameter to messenger/online.php, which displays the path in an error page due to an incorrect SQL stateme…
- CVE-2006-3561MEDIUMCVSS v2 5.0EG 5.02006-07-13
BT Voyager 2091 Wireless firmware 2.21.05.08m_A2pB018c1.d16d and earlier, and 3.01m and earlier, allow remote attackers to bypass the authentication process and gain sensitive information, such as configuration information via (1) /btvoyag…
- CVE-2006-4006MEDIUMCVSS v2 5.0EG 5.02006-08-07
The do_gameinfo function in BomberClone 0.11.6 and earlier, and possibly other functions, does not reset the packet data size, which causes the send_pkg function (packets.c) to use this data size when sending a reply, and allows remote att…
- CVE-2006-4136HIGHCVSS v2 7.5EG 7.52006-08-14
Multiple unspecified vulnerabilities in IBM WebSphere Application Server before 6.1.0.1 have unspecified impact and attack vectors involving (1) "SOAP requests and responses", (2) mbean, (3) ThreadIdentitySupport, and possibly others.
- CVE-2006-4223MEDIUMCVSS v2 5.0EG 5.02006-08-18
IBM WebSphere Application Server (WAS) before 6.0.2.13 allows context-dependent attackers to obtain sensitive information via unspecified vectors related to "JSP source code exposure" (PK23475), which occurs when ibm-web-ext.xmi sets fileS…
- CVE-2006-4537LOWCVSS v2 2.1EG 2.12006-09-05
NET$SESSION_CONTROL.EXE in DECnet-Plus in OpenVMS ALPHA 7.3-2 and Alpha 8.2 writes a password to an audit log file when there is a successful connection after a "network breakin" event, which allows local users to obtain passwords by readi…
- CVE-2006-4595MEDIUMCVSS v2 5.0EG 5.02006-09-07
muforum (µforum) 0.4c stores membres/members.dat under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as usernames and password hashes.
- CVE-2006-5229LOWCVSS v2 2.6EG 2.62006-10-10
OpenSSH portable 4.1 on SUSE Linux, and possibly other platforms and versions, and possibly under limited configurations, allows remote attackers to determine valid usernames via timing discrepancies in which responses take longer for vali…
- CVE-2006-5702MEDIUMCVSS v2 5.0EG 5.02006-11-04
Tikiwiki 1.9.5 allows remote attackers to obtain sensitive information (MySQL username and password) via an empty sort_mode parameter in (1) tiki-listpages.php, (2) tiki-lastchanges.php, (3) messu-archive.php, (4) messu-mailbox.php, (5) me…
- CVE-2006-5725MEDIUMCVSS v2 5.0EG 5.02006-11-04
The SSL server in AEP Smartgate 4.3b allows remote attackers to determine existence of directories via a direct request for a directory URI, which returns different HTTP status codes for existing and non-existing directories.
- CVE-2006-5858MEDIUMCVSS v2 5.0EG 5.02006-12-31
Adobe ColdFusion MX 7 through 7.0.2, and JRun 4, when run on Microsoft IIS, allows remote attackers to read arbitrary files, list directories, or read source code via a double URL-encoded NULL byte in a ColdFusion filename, such as a CFM f…
- CVE-2006-6457MEDIUMCVSS v2 5.0EG 5.02006-12-11
tiki-wiki_rss.php in Tikiwiki 1.9.5, 1.9.2, and possibly other versions allows remote attackers to obtain sensitive information (MySQL username and password) via an invalid (large or negative) ver parameter, which leaks the information in …
- CVE-2006-6637MEDIUMCVSS v2 5.0EG 5.02006-12-19
The Servlet Engine and Web Container in IBM WebSphere Application Server (WAS) before 6.0.2.17, when ibm-web-ext.xmi sets fileServingEnabled to true and servlet caching is enabled, allows remote attackers to obtain JSP source code and othe…
- CVE-2006-6735MEDIUMCVSS v2 5.0EG 5.02006-12-26
modules/viewcategory.php in Minh Nguyen Duong Obie Website Mini Web Shop 2.1.c allows remote attackers to obtain sensitive information via a request with an arbitrary catname parameter but no itemsdb parameter, which reveals the path in an…
- CVE-2006-6886MEDIUMCVSS v2 5.0EG 5.02006-12-31
phpwcms 1.2.5-DEV allows remote attackers to obtain sensitive information via a direct request for (1) files.public-userroot.inc.php or (2) files.private.additions.inc.php in include/inc_lib/, which reveals the path in various error messag…
- CVE-2006-6953LOWCVSS v2 2.1EG 2.12007-01-29
The virtual keyboard implementation in GlobeTrotter Mobility Manager changes the color of a key as it is pressed, which allows local users to capture arbitrary keystrokes, such as for passwords, by shoulder surfing or grabbing periodic scr…
- CVE-2006-6998MEDIUMCVSS v2 5.0EG 5.02007-02-12
install/loader_help.php in Headstart Solutions DeskPRO allows remote attackers to obtain configuration information via a q=phpinfo QUERY_STRING, which calls the phpinfo function.
- CVE-2006-6999MEDIUMCVSS v2 4.3EG 4.32007-02-12
attachment.php in Headstart Solutions DeskPRO allows remote attackers to read all uploaded files by providing the file number in a modified id parameter.
- CVE-2006-7086MEDIUMCVSS v2 4.3EG 4.32007-03-02
The (1) dlback.php and (2) dlback.cgi scripts in Hot Links allow remote attackers to obtain sensitive information and download the database via a direct request with a modified dl parameter.
- CVE-2007-0011MEDIUMCVSS v2 5.0EG 5.02007-11-05
The web portal interface in Citrix Access Gateway (aka Citrix Advanced Access Control) before Advanced Edition 4.5 HF1 places a session ID in the URL, which allows context-dependent attackers to hijack sessions by reading "residual informa…
- CVE-2007-0042HIGHCVSS v2 7.8EG 7.82007-07-10
Interpretation conflict in ASP.NET in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to access configuration files and obtain sensitive information, and possibly bypass secur…
- CVE-2007-0058HIGHCVSS v2 7.8EG 7.82007-01-04
Cisco Clean Access (CCA) 3.5.x through 3.5.9 and 3.6.x through 3.6.1.1 on the Clean Access Manager (CAM) allows remote attackers to bypass authentication and download arbitrary manual database backups by guessing the snapshot filename usin…
- CVE-2007-0259HIGHCVSS v2 7.8EG 7.82007-01-16
Ezboxx Portal System Beta 0.7.6 and earlier allows remote attackers to obtain sensitive information via an invalid cat parameter to boxx/knowledgebase.asp, which reveals the path in an error message.
- CVE-2007-0778MEDIUMCVSS v2 5.4EG 5.42007-02-26
The page cache feature in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 can generate hash collisions that cause page data to be appended to the wrong page cache, which allows remote attackers to obtain …
- CVE-2007-0979MEDIUMCVSS v2 5.0EG 5.02007-02-16
Unspecified vulnerability in LifeType before 1.1.6, and 1.2 before 1.2-beta2, allows remote attackers to obtain sensitive information (file contents) via a "crafted URL."
- CVE-2007-1044MEDIUMCVSS v2 5.0EG 5.02007-02-21
Pearson Education PowerSchool 4.3.6 allows remote attackers to list the contents of the admin folder via a URI composed of the admin/ directory name and an arbitrary filename ending in ".js." NOTE: it was later reported that this issue ha…
- CVE-2007-1116MEDIUMCVSS v2 5.0EG 5.02007-02-26
The CheckLoadURI function in Mozilla Firefox 1.8 lists the about: URI as a ChromeProtocol and can be loaded via JavaScript, which allows remote attackers to obtain sensitive information by querying the browser's session history.
- CVE-2007-1167MEDIUMCVSS v2 5.0EG 5.02007-03-02
inc/filebrowser/browser.php in deV!L`z Clanportal (DZCP) 1.4.5 and earlier allows remote attackers to obtain MySQL data via the inc/mysql.php value of the file parameter.
- CVE-2007-1194LOWCVSS v2 2.1EG 2.12007-03-02
Norman SandBox Analyzer does not use the proper range for Interrupt Descriptor Table (IDT) entries, which allows local users to determine that the local machine is an emulator, or a similar environment not based on a physical Intel process…
- CVE-2007-1237MEDIUMCVSS v2 5.0EG 5.02007-03-03
sitex allows remote attackers to obtain potentially sensitive information via a ' (quote) value for certain parameters, as demonstrated by parameters used in forum and search, which forces a SQL error.
- CVE-2007-1562MEDIUMCVSS v2 6.8EG 6.82007-03-21
The FTP protocol implementation in Mozilla Firefox before 1.5.0.11 and 2.x before 2.0.0.3 allows remote attackers to force the client to connect to other servers, perform a proxied port scan, or obtain sensitive information by specifying a…
- CVE-2007-1563MEDIUMCVSS v2 6.8EG 6.82007-03-21
The FTP protocol implementation in Opera 9.10 allows remote attackers to allows remote servers to force the client to connect to other servers, perform a proxied port scan, or obtain sensitive information by specifying an alternate server …
- CVE-2007-1564MEDIUMCVSS v2 6.8EG 6.82007-03-21
The FTP protocol implementation in Konqueror 3.5.5 allows remote servers to force the client to connect to other servers, perform a proxied port scan, or obtain sensitive information by specifying an alternate server address in an FTP PASV…
- CVE-2007-2022MEDIUMCVSS v2 6.8EG 6.82007-04-13
Adobe Macromedia Flash Player 7 and 9, when used with Opera before 9.20 or Konqueror before 20070613, allows remote attackers to obtain sensitive information (browser keystrokes), which are leaked to the Flash Player applet.
- CVE-2007-2253MEDIUMCVSS v2 5.0EG 5.02007-04-25
Exponent CMS 0.96.6 Alpha and earlier allows remote attackers to obtain path information via a direct request for (1) sdk/blanks/formcontrol.php and (2) sdk/blanks/file_modules.php.
- CVE-2007-2379MEDIUMCVSS v2 5.0EG 5.02007-04-30
The jQuery framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute…
- CVE-2007-2402MEDIUMCVSS v2 4.3EG 4.32007-07-15
QuickTime for Java in Apple Quicktime before 7.2 does not perform sufficient "access control," which allows remote attackers to obtain sensitive information (screen content) via crafted Java applets.
- CVE-2007-2479MEDIUMCVSS 5.9EG 5.92007-05-03
Cerulean Studios Trillian Pro before 3.1.5.1 allows remote attackers to obtain potentially sensitive information via long CTCP PING messages that contain UTF-8 characters, which generates a malformed response that is not truncated by a new…
- CVE-2007-2552MEDIUMCVSS v2 5.0EG 5.02007-05-09
The RecentChanges feature in WikkaWiki (Wikka Wiki) before 1.1.6.3 allows remote attackers to obtain the names, and possibly revision notes and dates, of private pages via RSS feeds.
- CVE-2007-2590MEDIUMCVSS v2 6.4EG 6.42007-05-11
Nokia Intellisync Mobile Suite 6.4.31.2, 6.6.0.107, and 6.6.2.2, possibly involving Novell Groupwise Mobile Server and Nokia Intellisync Wireless Email Express, allows remote attackers to obtain user names and other sensitive information v…
- CVE-2007-2748MEDIUMCVSS v2 4.3EG 4.32007-05-17
The substr_count function in PHP 5.2.1 and earlier allows context-dependent attackers to obtain sensitive information via unspecified vectors, a different affected function than CVE-2007-1375.
Map vulnerabilities like CWE-200 to your infrastructure
EchelonGraph correlates every CVE — across CWE-200 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →