{"api_version":"1","generated_at":"2026-07-23T09:46:20+00:00","cve":"CVE-1999-1206","urls":{"html":"https://cve.report/CVE-1999-1206","api":"https://cve.report/api/cve/CVE-1999-1206.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-1999-1206","nvd":"https://nvd.nist.gov/vuln/detail/CVE-1999-1206"},"summary":{"title":"CVE-1999-1206","description":"SystemSoft SystemWizard package in HP Pavilion PC with Windows 98, and possibly other platforms and operating systems, installs two ActiveX controls that are marked as safe for scripting, which allows remote attackers to execute arbitrary commands via a malicious web page that references (1) the Launch control, or (2) the RegObj control.","state":"PUBLISHED","assigner":"mitre","published_at":"1999-12-31 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.systemsoft.com/l-2/l-3/support-systemwizard.htm","name":"http://www.systemsoft.com/l-2/l-3/support-systemwizard.htm","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Technical Support - SystemWizard","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=93336970231857&w=2","name":"http://marc.info/?l=bugtraq&m=93336970231857&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'New ActiveX security problems in Windows 98 PCs' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/555","name":"http://www.securityfocus.com/bid/555","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SystemSoft SystemWizard ActiveX Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-1999-1206","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-1999-1206","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"1999","cve_id":"1206","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"systemsoft","cpe5":"systemwizard","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-01T17:02:53.771Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"19990729 New ActiveX security problems in Windows 98 PCs","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=93336970231857&w=2"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.systemsoft.com/l-2/l-3/support-systemwizard.htm"},{"name":"555","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/555"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"1999-07-22T00:00:00.000Z","descriptions":[{"lang":"en","value":"SystemSoft SystemWizard package in HP Pavilion PC with Windows 98, and possibly other platforms and operating systems, installs two ActiveX controls that are marked as safe for scripting, which allows remote attackers to execute arbitrary commands via a malicious web page that references (1) the Launch control, or (2) the RegObj control."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2016-10-17T13:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"19990729 New ActiveX security problems in Windows 98 PCs","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=93336970231857&w=2"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.systemsoft.com/l-2/l-3/support-systemwizard.htm"},{"name":"555","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/555"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-1999-1206","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"SystemSoft SystemWizard package in HP Pavilion PC with Windows 98, and possibly other platforms and operating systems, installs two ActiveX controls that are marked as safe for scripting, which allows remote attackers to execute arbitrary commands via a malicious web page that references (1) the Launch control, or (2) the RegObj control."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"19990729 New ActiveX security problems in Windows 98 PCs","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=93336970231857&w=2"},{"name":"http://www.systemsoft.com/l-2/l-3/support-systemwizard.htm","refsource":"CONFIRM","url":"http://www.systemsoft.com/l-2/l-3/support-systemwizard.htm"},{"name":"555","refsource":"BID","url":"http://www.securityfocus.com/bid/555"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-1999-1206","datePublished":"2001-09-12T04:00:00.000Z","dateReserved":"2001-08-31T00:00:00.000Z","dateUpdated":"2024-08-01T17:02:53.771Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"1999-12-31 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:systemsoft:systemwizard:*:*:*:*:*:*:*:*","matchCriteriaId":"E5B57640-D538-4DB5-8E68-7B06B08EEDE5"}]}]}]},"legacy_mitre":{"record":{"CveYear":"1999","CveId":"1206","Ordinal":"1","Title":"CVE-1999-1206","CVE":"CVE-1999-1206","Year":"1999"},"notes":[{"CveYear":"1999","CveId":"1206","Ordinal":"1","NoteData":"SystemSoft SystemWizard package in HP Pavilion PC with Windows 98, and possibly other platforms and operating systems, installs two ActiveX controls that are marked as safe for scripting, which allows remote attackers to execute arbitrary commands via a malicious web page that references (1) the Launch control, or (2) the RegObj control.","Type":"Description","Title":"CVE-1999-1206"},{"CveYear":"1999","CveId":"1206","Ordinal":"2","NoteData":"2001-09-12","Type":"Other","Title":"Published"},{"CveYear":"1999","CveId":"1206","Ordinal":"3","NoteData":"2016-10-17","Type":"Other","Title":"Modified"}]}}}