PT-1999-1619 · Microsoft · Internet Explorer
Published
1999-08-25
·
Updated
2021-07-22
·
CVE-1999-1235
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Internet Explorer version 5.0
Description
The issue allows local users to read sensitive information, such as usernames and passwords for FTP servers, from another user's index.dat file. Additionally, it enables individuals who are physically observing another user to read the information from the status bar when the user moves the mouse over a link.
Recommendations
For Internet Explorer version 5.0, consider clearing the URL history regularly to minimize the risk of exposing sensitive information. As a temporary workaround, users can also avoid storing sensitive information, such as usernames and passwords, in the URL history. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Internet Explorer