Vulnerabilities (CVE)

Filtered by CWE-425
Total 228 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-1697 1 Postnuke 1 Postnuke 2026-06-16 5.0 MEDIUM N/A
The RSS module in PostNuke 0.750 and 0.760RC2 and RC3 allows remote attackers to obtain sensitive information via a direct request to simple_smarty.php, which reveals the path in an error message.
CVE-2005-1688 1 Wordpress 1 Wordpress 2026-06-16 5.0 MEDIUM 5.3 MEDIUM
Wordpress 1.5 and earlier allows remote attackers to obtain sensitive information via a direct request to files in (1) wp-content/themes/, (2) wp-includes/, or (3) wp-admin/, which reveal the path in an error message.
CVE-2005-1685 1 Episodex 1 Episodex Guestbook 2026-06-16 7.5 HIGH N/A
episodex guestbook allows remote attackers to bypass authentication and edit scripts via a direct request to admin.asp.
CVE-2005-1668 1 Yusasp 1 Web Asset Manager 2026-06-16 7.5 HIGH N/A
YusASP Web Asset Manager 1.0 allows remote attackers to gain privileges via a direct request to assetmanager.asp.
CVE-2005-1654 1 Hostingcontroller 1 Hosting Controller 2026-06-16 7.5 HIGH N/A
Hosting Controller 6.1 Hotfix 1.9 and earlier allows remote attackers to register arbitrary users via a direct request to addsubsite.asp with the loginname and password parameters set.
CVE-2004-2257 1 Phpmyfaq 1 Phpmyfaq 2026-06-16 5.0 MEDIUM 5.3 MEDIUM
phpMyFAQ 1.4.0 allows remote attackers to access the Image Manager to upload or delete images without authorization via a direct request.
CVE-2004-2144 1 Baalsystems 1 Baal Smart Forms 2026-06-16 7.5 HIGH N/A
Baal Smart Forms before 3.2 allows remote attackers to bypass authentication and obtain system access via a direct request to regadmin.php.
CVE-2002-1798 1 Midicart 3 Midicart Php, Midicart Php Maxi, Midicart Php Plus 2026-06-16 6.4 MEDIUM 9.1 CRITICAL
MidiCart PHP, PHP Plus, and PHP Maxi allows remote attackers to (1) upload arbitrary php files via a direct request to admin/upload.php or (2) access sensitive information via a direct request to admin/credit_card_info.php.