CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
589 | CVE-1999-0607 | Candidate | quikstore.cgi in QuikStore shopping cart stores quikstore.cfg under the web document root with insufficient access control, which allows remote attackers to obtain the cleartext administrator password and gain privileges. | Modified (20060608) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Christey, Northcutt, Wall | Frech> XF:quikstore-misconfig(3858) | Christey> http://www.quikstore.com/help/pages/Security/security.htm says: | | "It is IMPORTANT that during the setup of the QuikStore program, you | check to make sure that the cgi-bin or executable program directory | of your web site not be viewable from the outside world. You don"t | want the users to have access to your programs or log files that could | be stored there! | | ... | | If you can view or download these files from the browser, someone | else can too" | | So is this a configuration problem? See the configuration file at | http://www.quikstore.com/help/pages/Configuration/configparametersfull.htm | The [DIRECTORY_PATHS] section identifies pathnames and describes how | pathnames are constructed. It clearly uses relative pathnames, | so all data is underneath the base directory!! | | If we call this a configuration problem, then maybe this (and | all other "CGI-data-in-web-tree" configuration problems) should | be combined. | Christey> Consider adding BID:1983 | View |
591 | CVE-1999-0609 | Candidate | An incorrect configuration of the SoftCart CGI program "SoftCart.exe" could disclose private information. | Proposed (19990728) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Christey, Northcutt, Wall | Frech> XF:softcart-misconfig(3856) | Christey> Consider adding BID:2055 | View |
6859 | CVE-2003-0030 | Candidate | Buffer overflows in protegrity.dll of Protegrity Secure.Data Extension Feature (SEF) before 2.2.3.9 allow attackers with SQL access to execute arbitrary code via the extended stored procedures (1) xp_pty_checkusers, (2) xp_pty_insert, or (3) xp_pty_select. | Modified (20080326) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Cole, Cox, Wall | Frech> XF:protegrity-sql-sp-bo(11528) | View |
5209 | CVE-2002-0819 | Candidate | Format string vulnerability in artsd, when called by artswrapper, allows local users to gain privileges via format strings in the -a argument, which results in an error message that is not properly handled in a call to the arts_fatal function. | Proposed (20020830) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Cole, Cox, Wall | REJECT(1) Foat | Foat> Artsd was supposedly vulnerable to a format string vulneraibity | resulting in elevated privileges because it called command (artscontrol) and was | installed suid root. The problem was supposed to affect Red Hat 7.2. We looked | at two different install of 7.2, neither of which had artsd nor artscontrol | installed suid root. | Frech> XF:artswrapper-artsd-format-string(9813) | View |
3210 | CVE-2001-0392 | Candidate | Navision Financials Server 2.60 and earlier allows remote attackers to cause a denial of service by sending a null character and a long string to the server port (2407), which causes the server to crash. | Proposed (20010524) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese | Frech> XF:navision-server-dos(6318) | View |
Page 625 of 20943, showing 5 records out of 104715 total, starting on record 3121, ending on 3125