PT-1999-1456 · Microsoft · Site Server
Published
1999-09-10
·
Updated
2018-10-12
·
CVE-1999-0910
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Site Server and Commercial Internet System (MCIS) (affected versions not specified)
Description
The issue is related to the fact that Microsoft Site Server and Commercial Internet System (MCIS) do not set an expiration for a cookie. This could allow the cookie to be cached by a proxy and inadvertently used by a different user.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Site Server