CVE-1999-1011
The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, which allows remote attackers to execute arbitrary commands.
- Affected products
- Iis, Data Access Components, Remote Data Service (Rds) Datafactory
- Microsoft Data Access Components
- = 1.5, 2.0, 2.1
- Microsoft Index Server
- = 2.0
- Microsoft Internet Information Server
- = 3.0, 4.0
- Microsoft Site Server
- = 3.0
- CVSS 2.0
- 10.0 HIGH
- EPSS
- 77.1% (100th percentile)
- Weakness
- CWE-264
- NVD status
- Modified
- Published
- 2000-06-02
CVE-1999-1011 at NVD
6 known exploits for CVE-1999-1011
Proof-of-concept code and exploit modules indexed by Sploitus
Microsoft IIS MDAC msadcs.dll RDS Arbitrary Remote Command Execution(ms98-004)
Microsoft IIS MDAC msadcs.dll RDS Arbitrary Remote Command Execution
Microsoft IIS MDAC msadcs.dll RDS Arbitrary Remote Command Execution
MS99-025 Microsoft IIS MDAC msadcs.dll RDS Arbitrary Remote Command Execution
Microsoft Data Access Components (MDAC) 2.1 / Microsoft IIS 3.0/4.0 / Microsoft Index Server 2.0 / Microsoft Site Server Commerce Edition 3.0 i386 MDAC - RDS (1)
Microsoft Data Access Components (MDAC) 2.1 / Microsoft IIS 3.0/4.0 / Microsoft Index Server 2.0 / Microsoft Site Server Commerce Edition 3.0 i386 MDAC - RDS (2)