Direct Mailer feature in Microsoft Site Server 3.0 saves user domain names and passwords in plaintext in the TMLBQueue network share, which has insecure default permissions, allowing remote attackers to read the passwords and gain privileges.
References
Link | Resource |
---|---|
http://support.microsoft.com/support/kb/articles/Q229/9/72.asp | Patch Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/2068 | |
http://support.microsoft.com/support/kb/articles/Q229/9/72.asp | Patch Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/2068 |
Configurations
History
20 Nov 2024, 23:30
Type | Values Removed | Values Added |
---|---|---|
References | () http://support.microsoft.com/support/kb/articles/Q229/9/72.asp - Patch, Vendor Advisory | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/2068 - |
Information
Published : 1999-12-31 05:00
Updated : 2024-11-20 23:30
NVD link : CVE-1999-1246
Mitre link : CVE-1999-1246
CVE.ORG link : CVE-1999-1246
JSON object : View
Products Affected
microsoft
- site_server
CWE