PT-1999-1568 · Microsoft · Internet Explorer

Publicado

1999-12-31

·

Atualizado

2021-07-22

·

CVE-1999-1087

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Internet Explorer version 4
Description The issue allows remote malicious web servers to conduct unauthorized activities by using URLs that contain a dotless IP address for their server. This occurs because Internet Explorer 4 treats a 32-bit number in a URL as the hostname instead of an IP address, causing it to apply Local Intranet Zone settings to the resulting web page.
Recommendations For Internet Explorer version 4, consider avoiding the use of dotless IP addresses in URLs until a fix is available. As a temporary workaround, restrict access to potentially malicious web servers to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-1999-1087

Produtos afetados

Internet Explorer