PT-2004-2435 · Microsoft · Internet Explorer

Keigo Yamazaki

·

Publicado

2004-12-31

·

Atualizado

2021-07-23

·

CVE-2004-1527

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Internet Explorer version 6.0 SP1
Description The issue arises from the improper handling of certain character strings in the Path attribute, allowing remote attackers to modify cookies in other domains. This can occur when the attacker's domain name is within the target's domain name or when wildcard DNS is being used, enabling the hijacking of web sessions.
Recommendations For Microsoft Internet Explorer version 6.0 SP1, consider applying configuration changes to restrict cookie access to prevent session hijacking until a proper fix is available. As a temporary workaround, restrict the use of wildcard DNS to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-1527

Produtos afetados

Internet Explorer