First published: Wed Aug 25 1999(Updated: )
Internet Explorer 5.0 records the username and password for FTP servers in the URL history, which could allow (1) local users to read the information from another user's index.dat, or (2) people who are physically observing ("shoulder surfing") another user to read the information from the status bar when the user moves the mouse over a link.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | =5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-1235 is considered to have a high severity due to the potential for exposed sensitive credentials.
To fix CVE-1999-1235, users should upgrade to a newer version of Internet Explorer that does not exhibit this vulnerability.
CVE-1999-1235 affects users of Internet Explorer 5.0, particularly those using FTP services.
The risks of CVE-1999-1235 include unauthorized access to FTP credentials by local users or physical onlookers.
The permanent solution for CVE-1999-1235 is to upgrade to a secure, updated web browser version.