Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Site_server
(Microsoft)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 16 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
1999-05-11 | CVE-1999-1520 | A configuration problem in the Ad Server Sample directory (AdSamples) in Microsoft Site Server 3.0 allows an attacker to obtain the SITE.CSC file, which exposes sensitive SQL database information. | Site_server | N/A | ||
1999-12-31 | CVE-1999-1451 | The Winmsdp.exe sample file in IIS 4.0 and Site Server 3.0 allows remote attackers to read arbitrary files. | Internet_information_server, Site_server | N/A | ||
1999-12-31 | CVE-1999-1246 | Direct Mailer feature in Microsoft Site Server 3.0 saves user domain names and passwords in plaintext in the TMLBQueue network share, which has insecure default permissions, allowing remote attackers to read the passwords and gain privileges. | Site_server | N/A | ||
1999-07-19 | CVE-1999-1011 | The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, which allows remote attackers to execute arbitrary commands. | Data_access_components, Index_server, Internet_information_server, Site_server | N/A | ||
1999-09-10 | CVE-1999-0910 | Microsoft Site Server and Commercial Internet System (MCIS) do not set an expiration for a cookie, which could then be cached by a proxy and inadvertently used by a different user. | Commercial_internet_system, Site_server, Site_server_commerce | N/A | ||
1999-01-30 | CVE-1999-0360 | MS Site Server 2.0 with IIS 4 can allow users to upload content, including ASP, to the target web site, thus allowing them to execute commands remotely. | Site_server | N/A |