CVE-1999-0870: Low severity Microsoft Internet Explorer vulnerability
Published Oct 1, 1998
·Updated
Internet Explorer 4.01 allows remote attackers to read arbitrary files by pasting a file name into the file upload control, aka untrusted scripted paste.
Affected Software
2 affected components
Microsoft Internet Explorer=4.0.1
Microsoft Internet Explorer=4.0.1-sp1
Event History
Oct 1, 1998
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
DescriptionSeverityAffected Software
Jan 4, 2000
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-1999-0870?
CVE-1999-0870 is classified as a medium severity vulnerability.
2
How do I fix CVE-1999-0870?
To mitigate CVE-1999-0870, it is recommended to upgrade to a version of Internet Explorer released after 4.0.1 that addresses this vulnerability.
3
What does CVE-1999-0870 allow an attacker to do?
CVE-1999-0870 allows remote attackers to read arbitrary files from a user's system by exploiting a vulnerability in the file upload control.
4
Which versions of Internet Explorer are affected by CVE-1999-0870?
CVE-1999-0870 affects Internet Explorer versions 4.0.1 and 4.0.1 SP1.
5
Is CVE-1999-0870 still a concern today?
While CVE-1999-0870 is an older vulnerability, users of legacy systems or software may still be at risk and should take precautions.