CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
586 | CVE-1999-0604 | Candidate | An incorrect configuration of the WebStore 1.0 shopping cart CGI program "web_store.cgi" could disclose private information. | Proposed (19990728) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(2) Northcutt, Wall | Frech> XF:webstore-misconfig(3861) | View |
587 | CVE-1999-0605 | Candidate | An incorrect configuration of the Order Form 1.0 shopping cart CGI program could disclose private information. | Proposed (19990728) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Christey, Northcutt, Wall | Frech> XF:orderform-misconfig(3860) | Christey> BID:2021 | Christey> Mention affected files: order_log_v12.dat and order_log.dat | fix version number (1.2) | View |
588 | CVE-1999-0606 | Candidate | An incorrect configuration of the EZMall 2000 shopping cart CGI program "mall2000.cgi" could disclose private information. | Proposed (19990728) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Christey, Northcutt, Wall | Frech> XF:ezmall2000-misconfig(3859) | Christey> Add mall_log_files/order.log to desc | View |
589 | CVE-1999-0607 | Candidate | quikstore.cgi in QuikStore shopping cart stores quikstore.cfg under the web document root with insufficient access control, which allows remote attackers to obtain the cleartext administrator password and gain privileges. | Modified (20060608) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Christey, Northcutt, Wall | Frech> XF:quikstore-misconfig(3858) | Christey> http://www.quikstore.com/help/pages/Security/security.htm says: | | "It is IMPORTANT that during the setup of the QuikStore program, you | check to make sure that the cgi-bin or executable program directory | of your web site not be viewable from the outside world. You don"t | want the users to have access to your programs or log files that could | be stored there! | | ... | | If you can view or download these files from the browser, someone | else can too" | | So is this a configuration problem? See the configuration file at | http://www.quikstore.com/help/pages/Configuration/configparametersfull.htm | The [DIRECTORY_PATHS] section identifies pathnames and describes how | pathnames are constructed. It clearly uses relative pathnames, | so all data is underneath the base directory!! | | If we call this a configuration problem, then maybe this (and | all other "CGI-data-in-web-tree" configuration problems) should | be combined. | Christey> Consider adding BID:1983 | View |
590 | CVE-1999-0608 | Entry | An incorrect configuration of the PDG Shopping Cart CGI program "shopper.cgi" could disclose private information. | View |
Page 118 of 20943, showing 5 records out of 104715 total, starting on record 586, ending on 590