CVE-1999-1011
10
CVSS SCORE
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C
Description
The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, which allows remote attackers to execute arbitrary commands.
CVSS Vector Details
Attack Vector
Network
Attack Complexity
Low
Confidentiality
C
Integrity
C
Availability
C
Affected Software Configurations
- a microsoft data_access_components 1.5 * * * * * * *
- a microsoft data_access_components 2.0 * * * * * * *
- a microsoft data_access_components 2.1 * * * * * * *
- a microsoft index_server 2.0 * * * * * * *
- a microsoft internet_information_server 3.0 * * * * * * *
- a microsoft internet_information_server 4.0 * * * * * * *
- a microsoft site_server 3.0 * * * * * * *
Weaknesses (CWE)
- CWE-264
References & External Links
- http://www.ciac.org/ciac/bulletins/j-054.shtml
- http://www.osvdb.org/272
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/1998/ms98-004
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-025
- https://www.securityfocus.com/bid/529
- http://www.ciac.org/ciac/bulletins/j-054.shtml
- http://www.osvdb.org/272
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/1998/ms98-004
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-025
- https://www.securityfocus.com/bid/529