Direct Mailer feature in Microsoft Site Server 3.0 saves user domain names and passwords in plaintext in the TMLBQueue network share, which has insecure default permissions, allowing remote attackers to read the passwords and gain privileges.
References
Link | Resource |
---|---|
http://support.microsoft.com/support/kb/articles/Q229/9/72.asp | Patch Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/2068 |
Configurations
Information
Published : 1999-12-30 21:00
Updated : 2017-10-09 18:29
NVD link : CVE-1999-1246
Mitre link : CVE-1999-1246
JSON object : View
CWE
Products Affected
microsoft
- site_server