PT-1999-1619 · Microsoft · Internet Explorer

Published

1999-08-25

·

Updated

2021-07-22

·

CVE-1999-1235

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Internet Explorer version 5.0
Description The issue allows local users to read sensitive information, such as usernames and passwords for FTP servers, from another user's index.dat file. Additionally, it enables individuals who are physically observing another user to read the information from the status bar when the user moves the mouse over a link.
Recommendations For Internet Explorer version 5.0, consider clearing the URL history regularly to minimize the risk of exposing sensitive information. As a temporary workaround, users can also avoid storing sensitive information, such as usernames and passwords, in the URL history. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-1999-1235

Affected Products

Internet Explorer