CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
589 | CVE-1999-0607 | Candidate | quikstore.cgi in QuikStore shopping cart stores quikstore.cfg under the web document root with insufficient access control, which allows remote attackers to obtain the cleartext administrator password and gain privileges. | Modified (20060608) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Christey, Northcutt, Wall | Frech> XF:quikstore-misconfig(3858) | Christey> http://www.quikstore.com/help/pages/Security/security.htm says: | | "It is IMPORTANT that during the setup of the QuikStore program, you | check to make sure that the cgi-bin or executable program directory | of your web site not be viewable from the outside world. You don"t | want the users to have access to your programs or log files that could | be stored there! | | ... | | If you can view or download these files from the browser, someone | else can too" | | So is this a configuration problem? See the configuration file at | http://www.quikstore.com/help/pages/Configuration/configparametersfull.htm | The [DIRECTORY_PATHS] section identifies pathnames and describes how | pathnames are constructed. It clearly uses relative pathnames, | so all data is underneath the base directory!! | | If we call this a configuration problem, then maybe this (and | all other "CGI-data-in-web-tree" configuration problems) should | be combined. | Christey> Consider adding BID:1983 | View |
591 | CVE-1999-0609 | Candidate | An incorrect configuration of the SoftCart CGI program "SoftCart.exe" could disclose private information. | Proposed (19990728) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Christey, Northcutt, Wall | Frech> XF:softcart-misconfig(3856) | Christey> Consider adding BID:2055 | View |
2717 | CVE-2000-1150 | Candidate | Felix IRC client in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that contains a long URL. | Proposed (20001219) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Armstrong, Cole, Wall | Frech> XF:felix-irc-long-url(5520) | View |
2718 | CVE-2000-1151 | Candidate | Baxter IRC client in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that contains a long URL. | Proposed (20001219) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Armstrong, Cole, Wall | Frech> XF:baxter-irc-bo(5518) | View |
2719 | CVE-2000-1152 | Candidate | Browser IRC client in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that contains a long URL. | Proposed (20001219) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Armstrong, Cole, Wall | Frech> XF:bowser-irc-dos(5964) | View |
Page 20320 of 20943, showing 5 records out of 104715 total, starting on record 101596, ending on 101600