CVE List

Id CVE No. Status Description Phase Votes Comments Actions
589  CVE-1999-0607  Candidate  quikstore.cgi in QuikStore shopping cart stores quikstore.cfg under the web document root with insufficient access control, which allows remote attackers to obtain the cleartext administrator password and gain privileges.  Modified (20060608)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Christey, Northcutt, Wall  Frech> XF:quikstore-misconfig(3858) | Christey> http://www.quikstore.com/help/pages/Security/security.htm says: | | "It is IMPORTANT that during the setup of the QuikStore program, you | check to make sure that the cgi-bin or executable program directory | of your web site not be viewable from the outside world. You don"t | want the users to have access to your programs or log files that could | be stored there! | | ... | | If you can view or download these files from the browser, someone | else can too" | | So is this a configuration problem? See the configuration file at | http://www.quikstore.com/help/pages/Configuration/configparametersfull.htm | The [DIRECTORY_PATHS] section identifies pathnames and describes how | pathnames are constructed. It clearly uses relative pathnames, | so all data is underneath the base directory!! | | If we call this a configuration problem, then maybe this (and | all other "CGI-data-in-web-tree" configuration problems) should | be combined. | Christey> Consider adding BID:1983  View
591  CVE-1999-0609  Candidate  An incorrect configuration of the SoftCart CGI program "SoftCart.exe" could disclose private information.  Proposed (19990728)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Christey, Northcutt, Wall  Frech> XF:softcart-misconfig(3856) | Christey> Consider adding BID:2055  View
2717  CVE-2000-1150  Candidate  Felix IRC client in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that contains a long URL.  Proposed (20001219)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Armstrong, Cole, Wall  Frech> XF:felix-irc-long-url(5520)  View
2718  CVE-2000-1151  Candidate  Baxter IRC client in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that contains a long URL.  Proposed (20001219)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Armstrong, Cole, Wall  Frech> XF:baxter-irc-bo(5518)  View
2719  CVE-2000-1152  Candidate  Browser IRC client in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that contains a long URL.  Proposed (20001219)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Armstrong, Cole, Wall  Frech> XF:bowser-irc-dos(5964)  View

Page 20320 of 20943, showing 5 records out of 104715 total, starting on record 101596, ending on 101600

Actions