PT-1999-1456 · Microsoft · Site Server

Published

1999-09-10

·

Updated

2018-10-12

·

CVE-1999-0910

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Site Server and Commercial Internet System (MCIS) (affected versions not specified)
Description The issue is related to the fact that Microsoft Site Server and Commercial Internet System (MCIS) do not set an expiration for a cookie. This could allow the cookie to be cached by a proxy and inadvertently used by a different user.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-1999-0910

Affected Products

Site Server