VulnerabilityModified
CVE-1999-1530
cgiwrap as used on Cobalt RaQ 2.0 and RaQ 3i does not properly identify the user for running certain scripts, which allows a malicious site administrator to view or modify data located at another virtual site on the same system.
LOW 3.6EPSS 0.36%
Does this matter?
Lower severity and a low EPSS score (0.36%). Track it; it rarely justifies an emergency change on its own.
Description
cgiwrap as used on Cobalt RaQ 2.0 and RaQ 3i does not properly identify the user for running certain scripts, which allows a malicious site administrator to view or modify data located at another virtual site on the same system.
- CVSS 2.0
- 3.6 LOWAV:L/AC:L/Au:N/C:P/I:P/A:N
- EPSS
- 0.36% probability · 30th percentile
- CISA KEV
- Not listed
- Affected
- sun/cobalt raq 2 · sun/cobalt raq 3i
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=94209954200450&w=2
- http://marc.info/?l=bugtraq&m=94225629200045&w=2
- http://www.iss.net/security_center/static/7764.php
- http://www.osvdb.org/35
- http://www.securityfocus.com/bid/777Patch, Vendor Advisory
- http://marc.info/?l=bugtraq&m=94209954200450&w=2
- http://marc.info/?l=bugtraq&m=94225629200045&w=2
- http://www.iss.net/security_center/static/7764.php
- http://www.osvdb.org/35
- http://www.securityfocus.com/bid/777Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.