Vulnerabilities > CVE-1999-1246 - Unspecified vulnerability in Microsoft Site Server 3.0
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
Direct Mailer feature in Microsoft Site Server 3.0 saves user domain names and passwords in plaintext in the TMLBQueue network share, which has insecure default permissions, allowing remote attackers to read the passwords and gain privileges.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |