Vulnerability Name: | CVE-2004-1527 (CCN-18073) | ||||||||
Assigned: | 2004-11-15 | ||||||||
Published: | 2004-11-15 | ||||||||
Updated: | 2021-07-23 | ||||||||
Summary: | Microsoft Internet Explorer 6.0 SP1 does not properly handle certain character strings in the Path attribute, which can cause it to modify cookies in other domains when the attacker's domain name is within the target's domain name or when wildcard DNS is being used, which allows remote attackers to hijack web sessions. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Data Manipulation | ||||||||
References: | Source: CCN Type: NTBugTraq Mailing List, Mon Nov 15 2004 - 03:01:07 CST A Possibility of Cookie Overwrite in Microsoft Internet Explorer Source: MITRE Type: CNA CVE-2004-1527 Source: BUGTRAQ Type: UNKNOWN 20041115 [SNS Advisory No.79] A Possibility of Cookie Overwrite in Microsoft Internet Explorer Source: CCN Type: SA13208 Microsoft Internet Explorer Cookie Path Attribute Vulnerability Source: SECUNIA Type: Patch 13208 Source: CCN Type: SNS Advisory No.79 A Possibility of Cookie Overwrite in Microsoft Internet Explorer Source: MISC Type: Patch, Vendor Advisory http://www.lac.co.jp/business/sns/intelligence/SNSadvisory_e/79_e.html Source: CCN Type: OSVDB ID: 11878 Microsoft IE Crafted Path Arbitrary Cookie Overwrite Source: BID Type: UNKNOWN 11680 Source: CCN Type: BID-11680 Microsoft Internet Explorer Cookie Overwrite Vulnerability Source: XF Type: UNKNOWN ie-path-cookie-overwrite(18073) Source: XF Type: UNKNOWN ie-path-cookie-overwrite(18073) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |