First published: Tue May 11 1999(Updated: )
A configuration problem in the Ad Server Sample directory (AdSamples) in Microsoft Site Server 3.0 allows an attacker to obtain the SITE.CSC file, which exposes sensitive SQL database information.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Site Server Commerce | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-1520 is classified as a medium severity vulnerability due to the potential exposure of sensitive SQL database information.
To fix CVE-1999-1520, ensure that proper access controls are implemented to restrict access to the Ad Server Sample directory.
CVE-1999-1520 specifically affects Microsoft Site Server version 3.0.
CVE-1999-1520 can expose sensitive SQL database connection details through the SITE.CSC file.
Yes, if you are using Microsoft Site Server 3.0 and do not secure the Ad Server Sample directory, your sensitive data may be at risk.