First published: Tue Aug 24 1999(Updated: )
Microsoft FrontPage stores form results in a default location in /_private/form_results.txt, which is world-readable and accessible in the document root, which allows remote attackers to read possibly sensitive information submitted by other users.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office FrontPage | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-1052 is considered a critical vulnerability due to the potential exposure of sensitive information.
To fix CVE-1999-1052, you should change the permissions of the /_private/form_results.txt file to prevent unauthorized access.
CVE-1999-1052 affects Microsoft FrontPage installations where form results are stored in the default location.
CVE-1999-1052 can expose sensitive information submitted by users through forms processed by Microsoft FrontPage.
While CVE-1999-1052 is an older vulnerability, it remains a risk in environments still using outdated Microsoft FrontPage software.