CVE-1999-0569
Published Jan 1, 1999A URL for a WWW directory allows auto-indexing, which provides a list of all files in that directory if it does not contain an index.html file.
Severity archive
43,635 critical severity CVEs — 43,635 Critical, 125,552 High, 163,859 Medium, 18,006 Low, 2,529 Unrated across the current result set.
A URL for a WWW directory allows auto-indexing, which provides a list of all files in that directory if it does not contain an index.html file.
Windows NT is not using a password filter utility, e.g. PASSFILT.DLL.
A router's configuration service or management interface (such as a web server or telnet) is configured to allow connections from arbitrary hosts.
A Windows NT system's file audit policy does not log an event success or failure for non-critical files or directories.
A Windows NT system's registry audit policy does not log an event success or failure for non-critical registry keys.
The HKEY_LOCAL_MACHINE key in a Windows NT system has inappropriate, system-critical permissions.
The HKEY_CLASSES_ROOT key in a Windows NT system has inappropriate, system-critical permissions.
There is a one-way or two-way trust relationship between Windows NT domains.
A Windows NT file system is not NTFS.
A WWW server is not running in a restricted file system, e.g. through a chroot, thus allowing access to system-critical data.
A system-critical Windows NT registry key has inappropriate permissions.
An event log in Windows NT has inappropriate access permissions.
The Logon box of a Windows NT system displays the name of the last user who logged in.
A Windows NT system does not restrict access to removable media drives such as a floppy disk drive or CDROM drive.
A Windows NT log file has an inappropriate maximum size or retention period.
A Windows NT account policy does not forcibly disconnect remote users from the server when their logon hours expire.
A network intrusion detection system (IDS) does not properly handle packets that are sent out of order, allowing an attacker to escape detection.
A network intrusion detection system (IDS) does not properly handle packets with improper sequence numbers.
A network intrusion detection system (IDS) does not verify the checksum on a packet.
A network intrusion detection system (IDS) does not properly handle data within TCP handshake packets.
A network intrusion detection system (IDS) does not properly reassemble fragmented packets.
In Windows NT, an inappropriate user is a member of a group, e.g. Administrator, Backup Operators, Domain Admins, Domain Guests, Power Users, Print Operators, Replicators, System…
A system-critical Windows NT registry key has an inappropriate value.
The rexec service is running.
The NT Alerter and Messenger services are running.