CVE List

Id CVE No. Status Description Phase Votes Comments Actions
586  CVE-1999-0604  Candidate  An incorrect configuration of the WebStore 1.0 shopping cart CGI program "web_store.cgi" could disclose private information.  Proposed (19990728)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(2) Northcutt, Wall  Frech> XF:webstore-misconfig(3861)  View
587  CVE-1999-0605  Candidate  An incorrect configuration of the Order Form 1.0 shopping cart CGI program could disclose private information.  Proposed (19990728)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Christey, Northcutt, Wall  Frech> XF:orderform-misconfig(3860) | Christey> BID:2021 | Christey> Mention affected files: order_log_v12.dat and order_log.dat | fix version number (1.2)  View
588  CVE-1999-0606  Candidate  An incorrect configuration of the EZMall 2000 shopping cart CGI program "mall2000.cgi" could disclose private information.  Proposed (19990728)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Christey, Northcutt, Wall  Frech> XF:ezmall2000-misconfig(3859) | Christey> Add mall_log_files/order.log to desc  View
589  CVE-1999-0607  Candidate  quikstore.cgi in QuikStore shopping cart stores quikstore.cfg under the web document root with insufficient access control, which allows remote attackers to obtain the cleartext administrator password and gain privileges.  Modified (20060608)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Christey, Northcutt, Wall  Frech> XF:quikstore-misconfig(3858) | Christey> http://www.quikstore.com/help/pages/Security/security.htm says: | | "It is IMPORTANT that during the setup of the QuikStore program, you | check to make sure that the cgi-bin or executable program directory | of your web site not be viewable from the outside world. You don"t | want the users to have access to your programs or log files that could | be stored there! | | ... | | If you can view or download these files from the browser, someone | else can too" | | So is this a configuration problem? See the configuration file at | http://www.quikstore.com/help/pages/Configuration/configparametersfull.htm | The [DIRECTORY_PATHS] section identifies pathnames and describes how | pathnames are constructed. It clearly uses relative pathnames, | so all data is underneath the base directory!! | | If we call this a configuration problem, then maybe this (and | all other "CGI-data-in-web-tree" configuration problems) should | be combined. | Christey> Consider adding BID:1983  View
590  CVE-1999-0608  Entry  An incorrect configuration of the PDG Shopping Cart CGI program "shopper.cgi" could disclose private information.        View

Page 118 of 20943, showing 5 records out of 104715 total, starting on record 586, ending on 590

Actions