CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3037 | CVE-2001-0216 | Candidate | PALS Library System pals-cgi program allows remote attackers to execute arbitrary commands via shell metacharacters in the documentName parameter. | Modified (20060609) | ACCEPT(2) Baker, Lawler | MODIFY(1) Frech | NOOP(2) Cole, Ziese | Frech> XF:webpals-library-cgi-url(6102) | View |
3038 | CVE-2001-0217 | Candidate | Directory traversal vulnerability in PALS Library System pals-cgi program allows remote attackers to read arbitrary files via a .. (dot dot) in the documentName parameter. | Modified (20060609) | ACCEPT(1) Baker | MODIFY(2) Frech, Lawler | NOOP(2) Cole, Ziese | Lawler> Combine with CVE-2001-0216 | Frech> XF:webpals-library-cgi-url(6102) | View |
3045 | CVE-2001-0224 | Candidate | Muscat Empower CGI program allows remote attackers to obtain the absolute pathname of the server via an invalid request in the DB parameter. | Modified (20060609) | MODIFY(1) Frech | NOOP(3) Cole, Lawler, Ziese | Frech> XF:muskat-empower-url-dir(6093) | View |
589 | CVE-1999-0607 | Candidate | quikstore.cgi in QuikStore shopping cart stores quikstore.cfg under the web document root with insufficient access control, which allows remote attackers to obtain the cleartext administrator password and gain privileges. | Modified (20060608) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Christey, Northcutt, Wall | Frech> XF:quikstore-misconfig(3858) | Christey> http://www.quikstore.com/help/pages/Security/security.htm says: | | "It is IMPORTANT that during the setup of the QuikStore program, you | check to make sure that the cgi-bin or executable program directory | of your web site not be viewable from the outside world. You don"t | want the users to have access to your programs or log files that could | be stored there! | | ... | | If you can view or download these files from the browser, someone | else can too" | | So is this a configuration problem? See the configuration file at | http://www.quikstore.com/help/pages/Configuration/configparametersfull.htm | The [DIRECTORY_PATHS] section identifies pathnames and describes how | pathnames are constructed. It clearly uses relative pathnames, | so all data is underneath the base directory!! | | If we call this a configuration problem, then maybe this (and | all other "CGI-data-in-web-tree" configuration problems) should | be combined. | Christey> Consider adding BID:1983 | View |
632 | CVE-1999-0650 | Candidate | The netstat service is running, which provides sensitive information to remote attackers. | Modified (20060608) | ACCEPT(2) Baker, Wall | REJECT(1) Northcutt | View |
Page 489 of 20943, showing 5 records out of 104715 total, starting on record 2441, ending on 2445