CVE-1999-1052: Medium severity microsoft frontpage vulnerability

Published Aug 24, 1999
·
Updated

Microsoft FrontPage stores form results in a default location in /private/formresults.txt, which is world-readable and accessible in the document root, which allows remote attackers to read possibly sensitive information submitted by other users.

Affected Software

1 affected component
Microsoft FrontPage

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Configure FrontPage so form results are stored outside the web document root (do not store results in /_private/form_results.txt in the site root).

    Microsoft Office FrontPage form_results_storage_location = outside document root
  2. Configuration

    Change file system permissions on form results so the file is not world-readable (remove public/read access and restrict to the web server or administrator accounts only).

    Microsoft Office FrontPage form_results_file_permissions = not world-readable
  3. Compensating control

    Configure the web server or site access controls to deny HTTP access to /_private/form_results.txt and the /_private directory (for example, return 403 or restrict access to trusted IPs) to prevent remote reads.

  4. Operational

    Search the document root for any existing /_private/form_results.txt files, securely delete or move them outside the document root, and sanitize any sensitive data contained within.

Event History

Aug 24, 1999
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
DescriptionSeverityAffected Software
Sep 12, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-1999-1052?

CVE-1999-1052 is considered a critical vulnerability due to the potential exposure of sensitive information.

2

How do I fix CVE-1999-1052?

To fix CVE-1999-1052, you should change the permissions of the /_private/form_results.txt file to prevent unauthorized access.

3

What systems are impacted by CVE-1999-1052?

CVE-1999-1052 affects Microsoft FrontPage installations where form results are stored in the default location.

4

What type of information can be exposed by CVE-1999-1052?

CVE-1999-1052 can expose sensitive information submitted by users through forms processed by Microsoft FrontPage.

5

Is CVE-1999-1052 still a risk today?

While CVE-1999-1052 is an older vulnerability, it remains a risk in environments still using outdated Microsoft FrontPage software.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203