Skip to main content

Vendor/product archive

microsoft / site_server CVEs

Beta · best-effort

15 CVEs tagged to microsoft / site_server1 Critical, 4 High, 9 Medium, 1 Low, 0 Unrated.

CVE-2000-0161

Published Feb 18, 2000

Sample web sites on Microsoft Site Server 3.0 Commerce Edition do not validate an identification number, which allows remote attackers to execute SQL commands.

CVSS 7.5 · High
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-1999-1246

Published Dec 31, 1999

Direct Mailer feature in Microsoft Site Server 3.0 saves user domain names and passwords in plaintext in the TMLBQueue network share, which has insecure default permissions, allow…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-1999-1520

Published May 11, 1999

A configuration problem in the Ad Server Sample directory (AdSamples) in Microsoft Site Server 3.0 allows an attacker to obtain the SITE.CSC file, which exposes sensitive SQL data…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-1999-0360

Published Jan 30, 1999

MS Site Server 2.0 with IIS 4 can allow users to upload content, including ASP, to the target web site, thus allowing them to execute commands remotely.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort
Showing 1-15 of 15 CVEsPage 1 of 1