3255 vulnerabilities classified as CWE-200 (信息暴露). AI Chinese analysis included.
CWE-200 represents a critical information disclosure weakness where software inadvertently reveals sensitive data to unauthorized entities. This vulnerability is typically exploited by attackers who leverage insufficient access controls, insecure direct object references, or verbose error messages to harvest credentials, personal identifiable information, or internal system details. By analyzing network traffic or manipulating application inputs, adversaries can extract this exposed data to facilitate further attacks, such as identity theft or privilege escalation. To mitigate this risk, developers must implement strict access control mechanisms, ensuring that data retrieval is validated against user permissions. Additionally, employing robust encryption for data at rest and in transit, along with sanitizing error outputs to prevent information leakage, significantly reduces the attack surface. Regular security audits and adherence to the principle of least privilege further ensure that sensitive information remains protected from unauthorized exposure.
my $username=param('username'); my $password=param('password'); if (IsValidUsername($username) == 1) { if (IsValidPassword($username, $password) == 1) { print "Login Successful"; } else { print "Login Failed - incorrect password"; } } else { print "Login Failed - unknown username"; }
"Login Failed - incorrect username or password"
try { openDbConnection(); } //print exception message that includes exception message and configuration file location catch (Exception $e) { echo 'Caught exception: ', $e->getMessage(), '\n'; echo 'Check credentials in config file at: ', $Mysql_config_location, '\n'; }
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2017-12169 | Red Hat FreeIPA 信息泄露漏洞 — ipa | 4.3 | - | 2018-01-10 |
| CVE-2017-5262 | Cambium Networks cnPilot 安全漏洞 — cnPilot | 8.1 | - | 2017-12-20 |
| CVE-2017-12373 | 多款Cisco产品信息泄露漏洞 — Cisco legacy ASA 5500 products TLS protocol implementation | 5.9 | - | 2017-12-15 |
| CVE-2017-12080 | Synology Photo Station 信息泄露漏洞 — Photo Station | 7.5 | - | 2017-12-04 |
| CVE-2017-12354 | Cisco Secure Access Control System 信息泄露漏洞 — Cisco Secure Access Control System | 5.3 | - | 2017-11-30 |
| CVE-2017-12361 | Cisco Jabber for Windows 信息泄露漏洞 — Cisco Jabber | 6.2 | - | 2017-11-30 |
| CVE-2017-12365 | Cisco WebEx Event Center 信息泄露漏洞 — Cisco WebEx Event Center | 4.3 | - | 2017-11-30 |
| CVE-2017-15099 | PostgreSQL 安全漏洞 — postgresql | 7.5 | - | 2017-11-22 |
| CVE-2017-15098 | PostgreSQL 安全漏洞 — postgresql | 8.1 | - | 2017-11-22 |
| CVE-2017-16715 | Moxa NPort 5110、5130和5150 信息泄露漏洞 — Moxa NPort 5110, 5130, and 5150 | 7.5 | - | 2017-11-16 |
| CVE-2017-12315 | Cisco HyperFlex System system logging 信息泄露漏洞 — Cisco HyperFlex System | 6.0 | - | 2017-11-16 |
| CVE-2017-9369 | BlackBerry QNX Software Development Platform 信息泄露漏洞 — QNX Software Development Platform (SDP) | 3.8 | Low | 2017-11-14 |
| CVE-2017-15087 | Red Hat Enterprise Linux Gluster Storage 安全漏洞 — Gluster Storage for RHEL 6 | 5.9 | - | 2017-11-08 |
| CVE-2017-12279 | Cisco Aironet Access Points IOS Software 信息泄露漏洞 — Cisco IOS Software for Cisco Aironet Access Points | 6.5 | - | 2017-11-02 |
| CVE-2017-12295 | Cisco WebEx Meetings Server 信息泄露漏洞 — Cisco WebEx Meetings Server | 5.3 | - | 2017-11-02 |
| CVE-2017-12284 | Cisco Jabber for Windows Client 信息泄露漏洞 — Cisco Jabber for Windows Client | 5.5 | - | 2017-10-19 |
| CVE-2017-12289 | Cisco IOS XE Software 安全漏洞 — Cisco IOS XE | 4.4 | - | 2017-10-19 |
| CVE-2017-14009 | ProMinent MultiFLEX M10a Controller Web界面信息泄露漏洞 — ProMinent MultiFLEX M10a Controller | 6.5 | - | 2017-10-17 |
| CVE-2017-9628 | Saia Burgess Controls PCD Controller 信息泄露漏洞 — Saia Burgess Controls PCD Controllers | 5.3 | - | 2017-10-04 |
| CVE-2017-12216 | Cisco SocialMiner 安全漏洞 — Cisco SocialMiner | 8.8 | - | 2017-09-07 |
| CVE-2017-12224 | Cisco Meeting Server 信息泄露漏洞 — Cisco Meeting Server | 5.5 | - | 2017-09-07 |
| CVE-2017-6793 | Cisco Prime Collaboration Provisioning Tool 信息泄露漏洞 — Cisco Prime Collaboration Provisioning Tool | 6.5 | - | 2017-09-07 |
| CVE-2017-6752 | Cisco Adaptive Security Appliance 信息泄露漏洞 — Cisco Adaptive Security Appliance | 5.3 | - | 2017-08-07 |
| CVE-2017-6708 | Cisco Ultra Services Framework 信息泄露漏洞 — Cisco Ultra Services Framework | 9.8 | - | 2017-07-06 |
| CVE-2017-6709 | Cisco Ultra Services Framework AutoVNF工具信息泄露漏洞 — Cisco Ultra Services Framework | 9.8 | - | 2017-07-06 |
| CVE-2017-6040 | Belden Hirschmann GECKO Lite Managed Switch 信息泄露漏洞 — Belden Hirschmann GECKO | 5.3 | - | 2017-06-30 |
| CVE-2017-7899 | 多款Rockwell Automation产品信息泄露漏洞 — Rockwell Automation Allen-Bradley MicroLogix 1100 and 1400 | 7.5 | - | 2017-06-30 |
| CVE-2017-7520 | OpenVPN 安全漏洞 — OpenVPN | 7.4 | - | 2017-06-27 |
| CVE-2017-6642 | Cisco Remote Expert Manager Software 信息泄露漏洞 — Cisco Remote Expert Manager | 5.3 | - | 2017-05-22 |
| CVE-2017-6643 | Cisco Remote Expert Manager Software 信息泄露漏洞 — Cisco Remote Expert Manager | 5.3 | - | 2017-05-22 |
Vulnerabilities classified as CWE-200 (信息暴露) represent 3255 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.