CVE-1999-1246: Direct Mailer feature in Microsoft Site Server 3.0 saves user domain names and passwords in plaintext in the TMLBQueue n
Summary
Direct Mailer feature in Microsoft Site Server 3.0 saves user domain names and passwords in plaintext in the TMLBQueue network share, which has insecure default permissions, allowing remote attackers to read the passwords and gain privileges.
Severity
UNKNOWN
Source Attribution
Source: NVD · Updated: 2026-08-21T04:30:53.031Z · Confidence: high
Impact
Based on CVSS vector: n/a — assess confidentiality, integrity, and availability impact via the official vector documentation.
Affected Software
Fix
Upgrade affected software to the fixed version identified above. Apply vendor patches and monitor advisories before exposed systems go unpatched.