First published: Tue Jan 26 1999(Updated: )
Internet Explorer 4.01 allows remote attackers to read local files and spoof web pages via a "%01" character in an "about:" Javascript URL, which causes Internet Explorer to use the domain specified after the character.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-0347 is classified as a critical vulnerability due to its potential for remote file reading and spoofing attacks.
To fix CVE-1999-0347, users should upgrade to a newer version of Internet Explorer that is not affected by this vulnerability.
Attackers can exploit CVE-1999-0347 to read local files and spoof web pages, potentially leading to information disclosure.
CVE-1999-0347 specifically affects Internet Explorer 4.01 and may not impact later versions.
If updating is not possible, avoid using Internet Explorer 4.01 for browsing and consider using an alternative browser.