CVE-1999-0283
Published Jan 1, 1999The Java Web Server would allow remote users to obtain the source code for CGI programs.
Severity archive
43,512 critical severity CVEs — 43,512 Critical, 125,296 High, 163,627 Medium, 17,990 Low, 2,330 Unrated across the current result set.
The Java Web Server would allow remote users to obtain the source code for CGI programs.
Denial of service in telnet from the Windows NT Resource Kit, by opening then immediately closing a connection.
In some NT web servers, appending a space at the end of a URL may allow attackers to read source code for active pages.
NetWare version of LaserFiche stores usernames and passwords unencrypted, and allows administrative changes without logging.
Microsoft Access 97 stores a database password as plaintext in a foreign mdb, allowing access to data.
DPEC Online Courseware allows an attacker to change another user's password without knowing the original password.
The demo version of the Quakenbush NT Password Appraiser sends passwords across the network in plaintext.
A service or application has a backdoor password that was placed there by the developer.
A remote attacker can sometimes identify the operating system of a host based on how it reacts to some IP or ICMP packets, using a tool such as nmap or queso.
Remote attackers can crash Lynx and Internet Explorer using an IMG tag with a large width parameter.
A remote attacker can gain access to a file system using .. (dot dot) when accessing SMB shares.
A mail server is explicitly configured to allow SMTP mail relay, which allows abuse by spammers.
An unrestricted remote trust relationship for Unix systems has been set up, e.g. by using a + sign in /etc/hosts.equiv.
The permissions for system-critical data in an anonymous FTP account are inappropriate. For example, the root directory is writeable by world, a real password file is obtainable,…
A system is operating in "promiscuous" mode which allows it to perform packet sniffing.
A trust relationship exists between two Unix hosts.
An SSH server allows authentication through the .rhosts file.
A superfluous NFS server is running, but it is not importing or exporting any file systems.
NFS exports system-critical data to the world, e.g. / or a password file.
A Unix account with a name other than "root" has UID 0, i.e. root privileges.
Two or more Unix accounts have the same UID.
A system-critical Unix file or directory has inappropriate permissions.
A system-critical Windows NT file or directory has inappropriate permissions.
IIS has the #exec function enabled for Server Side Include (SSI) files.
An attacker can force a printer to print arbitrary documents (e.g. if the printer doesn't require a password) or to become disabled.