CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1485  CVE-1999-1505  Candidate  Buffer overflow in QuakeWorld 2.10 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary commands via a long initial connect packet.  Proposed (20010912)  MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall  Frech> XF:quakeworld-connect-bo(7356)  View
2755  CVE-2000-1188  Candidate  Directory traversal vulnerability in Quikstore shopping cart program allows remote attackers to read arbitrary files via a .. (dot dot) attack in the "page" parameter.  Modified (20060413)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Armstrong, Cole, Wall  Frech> XF:quikstore-cgi-read-files(5561) | Armstrong> in Description: change rmeote to remote.  View
589  CVE-1999-0607  Candidate  quikstore.cgi in QuikStore shopping cart stores quikstore.cfg under the web document root with insufficient access control, which allows remote attackers to obtain the cleartext administrator password and gain privileges.  Modified (20060608)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Christey, Northcutt, Wall  Frech> XF:quikstore-misconfig(3858) | Christey> http://www.quikstore.com/help/pages/Security/security.htm says: | | "It is IMPORTANT that during the setup of the QuikStore program, you | check to make sure that the cgi-bin or executable program directory | of your web site not be viewable from the outside world. You don"t | want the users to have access to your programs or log files that could | be stored there! | | ... | | If you can view or download these files from the browser, someone | else can too" | | So is this a configuration problem? See the configuration file at | http://www.quikstore.com/help/pages/Configuration/configparametersfull.htm | The [DIRECTORY_PATHS] section identifies pathnames and describes how | pathnames are constructed. It clearly uses relative pathnames, | so all data is underneath the base directory!! | | If we call this a configuration problem, then maybe this (and | all other "CGI-data-in-web-tree" configuration problems) should | be combined. | Christey> Consider adding BID:1983  View
3308  CVE-2001-0491  Candidate  Directory traversal vulnerability in RaidenFTPD Server 2.1 before build 952 allows attackers to access files outside the ftp root via dot dot attacks, such as (1) .... in CWD, (2) .. in NLST, or (3) ... in NLST.  Modified (20010910-01)  ACCEPT(1) Williams | MODIFY(2) Baker, Frech | NOOP(4) Cole, Renaud, Wall, Ziese  Frech> XF:raidenftpd-dot-directory-traversal(6455) | Baker> Should probably modify description to say v2.1 prior to build 952, since the interim builds also had similar problems until build 952 resolved this.  View
3300  CVE-2001-0483  Candidate  Configuration error in Axent Raptor Firewall 6.5 allows remote attackers to use the firewall as a proxy to access internal web resources when the http.noproxy Rule is not set.  Proposed (20010524)  ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(2) Wall, Ziese  Frech> XF:raptor-http-access-ports(6313)  View

Page 20845 of 20943, showing 5 records out of 104715 total, starting on record 104221, ending on 104225

Actions