CVE List

Id CVE No. Status Description Phase Votes Comments Actions
589  CVE-1999-0607  Candidate  quikstore.cgi in QuikStore shopping cart stores quikstore.cfg under the web document root with insufficient access control, which allows remote attackers to obtain the cleartext administrator password and gain privileges.  Modified (20060608)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Christey, Northcutt, Wall  Frech> XF:quikstore-misconfig(3858) | Christey> http://www.quikstore.com/help/pages/Security/security.htm says: | | "It is IMPORTANT that during the setup of the QuikStore program, you | check to make sure that the cgi-bin or executable program directory | of your web site not be viewable from the outside world. You don"t | want the users to have access to your programs or log files that could | be stored there! | | ... | | If you can view or download these files from the browser, someone | else can too" | | So is this a configuration problem? See the configuration file at | http://www.quikstore.com/help/pages/Configuration/configparametersfull.htm | The [DIRECTORY_PATHS] section identifies pathnames and describes how | pathnames are constructed. It clearly uses relative pathnames, | so all data is underneath the base directory!! | | If we call this a configuration problem, then maybe this (and | all other "CGI-data-in-web-tree" configuration problems) should | be combined. | Christey> Consider adding BID:1983  View
591  CVE-1999-0609  Candidate  An incorrect configuration of the SoftCart CGI program "SoftCart.exe" could disclose private information.  Proposed (19990728)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Christey, Northcutt, Wall  Frech> XF:softcart-misconfig(3856) | Christey> Consider adding BID:2055  View
6859  CVE-2003-0030  Candidate  Buffer overflows in protegrity.dll of Protegrity Secure.Data Extension Feature (SEF) before 2.2.3.9 allow attackers with SQL access to execute arbitrary code via the extended stored procedures (1) xp_pty_checkusers, (2) xp_pty_insert, or (3) xp_pty_select.  Modified (20080326)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Cole, Cox, Wall  Frech> XF:protegrity-sql-sp-bo(11528)  View
5209  CVE-2002-0819  Candidate  Format string vulnerability in artsd, when called by artswrapper, allows local users to gain privileges via format strings in the -a argument, which results in an error message that is not properly handled in a call to the arts_fatal function.  Proposed (20020830)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Cole, Cox, Wall | REJECT(1) Foat  Foat> Artsd was supposedly vulnerable to a format string vulneraibity | resulting in elevated privileges because it called command (artscontrol) and was | installed suid root. The problem was supposed to affect Red Hat 7.2. We looked | at two different install of 7.2, neither of which had artsd nor artscontrol | installed suid root. | Frech> XF:artswrapper-artsd-format-string(9813)  View
3210  CVE-2001-0392  Candidate  Navision Financials Server 2.60 and earlier allows remote attackers to cause a denial of service by sending a null character and a long string to the server port (2407), which causes the server to crash.  Proposed (20010524)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese  Frech> XF:navision-server-dos(6318)  View

Page 625 of 20943, showing 5 records out of 104715 total, starting on record 3121, ending on 3125

Actions