PT-2005-3700 · Microsoft · Internet Explorer
Publicado
2005-12-14
·
Atualizado
2021-07-23
·
CVE-2005-2830
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Internet Explorer versions 5.01, 5.5, and 6
Description
The issue allows remote attackers to obtain sensitive information when using an HTTPS proxy server that requires Basic Authentication, as URLs are sent in cleartext.
Recommendations
For Microsoft Internet Explorer versions 5.01, 5.5, and 6, consider configuring the HTTPS proxy server to not require Basic Authentication, or use an alternative authentication method to minimize the risk of sensitive information exposure.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Internet Explorer