CVE-1999-1246

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
31/12/1999
Last modified:
03/04/2025

Description

Direct Mailer feature in Microsoft Site Server 3.0 saves user domain names and passwords in plaintext in the TMLBQueue network share, which has insecure default permissions, allowing remote attackers to read the passwords and gain privileges.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:microsoft:site_server:3.0:*:*:*:*:*:*:*