PT-2004-2435 · Microsoft · Internet Explorer

Keigo Yamazaki

·

Published

2004-12-31

·

Updated

2021-07-23

·

CVE-2004-1527

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Internet Explorer version 6.0 SP1
Description The issue arises from the improper handling of certain character strings in the Path attribute, allowing remote attackers to modify cookies in other domains. This can occur when the attacker's domain name is within the target's domain name or when wildcard DNS is being used, enabling the hijacking of web sessions.
Recommendations For Microsoft Internet Explorer version 6.0 SP1, consider applying configuration changes to restrict cookie access to prevent session hijacking until a proper fix is available. As a temporary workaround, restrict the use of wildcard DNS to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-1527

Affected Products

Internet Explorer