CVE-1999-1246
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
31/12/1999
Last modified:
03/04/2025
Description
Direct Mailer feature in Microsoft Site Server 3.0 saves user domain names and passwords in plaintext in the TMLBQueue network share, which has insecure default permissions, allowing remote attackers to read the passwords and gain privileges.
Impact
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:microsoft:site_server:3.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page