Vulnerability Name:

CVE-1999-1530 (CCN-7764)

Assigned:1999-11-08
Published:1999-11-08
Updated:2016-10-18
Summary:cgiwrap as used on Cobalt RaQ 2.0 and RaQ 3i does not properly identify the user for running certain scripts, which allows a malicious site administrator to view or modify data located at another virtual site on the same system.
CVSS v3 Severity:5.1 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:3.6 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
3.6 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-Other
Vulnerability Consequences:Data Manipulation
References:Source: CCN
Type: BugTraq Mailing List, Mon, 8 Nov 1999 11:41:02 -0600
Security flaw in Cobalt RaQ2 cgiwrap

Source: CCN
Type: BugTraq Mailing List, Tue, 9 Nov 1999 15:09:39 -0800
[Cobalt] Security Advisory - cgiwrap

Source: MITRE
Type: CNA
CVE-1999-1530

Source: BUGTRAQ
Type: UNKNOWN
19991108 Security flaw in Cobalt RaQ2 cgiwrap

Source: BUGTRAQ
Type: UNKNOWN
19991109 [Cobalt] Security Advisory - cgiwrap

Source: XF
Type: UNKNOWN
cobalt-cgiwrap-incorrect-permissions(7764)

Source: OSVDB
Type: UNKNOWN
35

Source: CCN
Type: OSVDB ID: 35
Cobalt RaQ cgiwrap Site Information Disclosure

Source: BID
Type: Patch, Vendor Advisory
777

Source: CCN
Type: BID-777
Cobalt RaQ2 cgiwrap Vulnerability

Source: XF
Type: UNKNOWN
cobalt-cgiwrap-incorrect-permissions(7764)

Vulnerable Configuration:Configuration 1:
  • cpe:/h:sun:cobalt_raq_2:*:*:*:*:*:*:*:*
  • OR cpe:/h:sun:cobalt_raq_3i:*:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/h:sun:cobalt_raq_2:*:*:*:*:*:*:*:*
  • OR cpe:/h:sun:cobalt_raq_3i:*:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    sun cobalt raq 2 *
    sun cobalt raq 3i *
    sun cobalt raq 2 *
    sun cobalt raq 3i *