CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3037  CVE-2001-0216  Candidate  PALS Library System pals-cgi program allows remote attackers to execute arbitrary commands via shell metacharacters in the documentName parameter.  Modified (20060609)  ACCEPT(2) Baker, Lawler | MODIFY(1) Frech | NOOP(2) Cole, Ziese  Frech> XF:webpals-library-cgi-url(6102)  View
3038  CVE-2001-0217  Candidate  Directory traversal vulnerability in PALS Library System pals-cgi program allows remote attackers to read arbitrary files via a .. (dot dot) in the documentName parameter.  Modified (20060609)  ACCEPT(1) Baker | MODIFY(2) Frech, Lawler | NOOP(2) Cole, Ziese  Lawler> Combine with CVE-2001-0216 | Frech> XF:webpals-library-cgi-url(6102)  View
3045  CVE-2001-0224  Candidate  Muscat Empower CGI program allows remote attackers to obtain the absolute pathname of the server via an invalid request in the DB parameter.  Modified (20060609)  MODIFY(1) Frech | NOOP(3) Cole, Lawler, Ziese  Frech> XF:muskat-empower-url-dir(6093)  View
589  CVE-1999-0607  Candidate  quikstore.cgi in QuikStore shopping cart stores quikstore.cfg under the web document root with insufficient access control, which allows remote attackers to obtain the cleartext administrator password and gain privileges.  Modified (20060608)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Christey, Northcutt, Wall  Frech> XF:quikstore-misconfig(3858) | Christey> http://www.quikstore.com/help/pages/Security/security.htm says: | | "It is IMPORTANT that during the setup of the QuikStore program, you | check to make sure that the cgi-bin or executable program directory | of your web site not be viewable from the outside world. You don"t | want the users to have access to your programs or log files that could | be stored there! | | ... | | If you can view or download these files from the browser, someone | else can too" | | So is this a configuration problem? See the configuration file at | http://www.quikstore.com/help/pages/Configuration/configparametersfull.htm | The [DIRECTORY_PATHS] section identifies pathnames and describes how | pathnames are constructed. It clearly uses relative pathnames, | so all data is underneath the base directory!! | | If we call this a configuration problem, then maybe this (and | all other "CGI-data-in-web-tree" configuration problems) should | be combined. | Christey> Consider adding BID:1983  View
632  CVE-1999-0650  Candidate  The netstat service is running, which provides sensitive information to remote attackers.  Modified (20060608)  ACCEPT(2) Baker, Wall | REJECT(1) Northcutt    View

Page 489 of 20943, showing 5 records out of 104715 total, starting on record 2441, ending on 2445

Actions