First published: Thu May 11 2000(Updated: )
Internet Explorer 4.0 and 5.0 allows a malicious web site to obtain client cookies from another domain by including that domain name and escaped characters in a URL, aka the "Unauthorized Cookie Access" vulnerability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | =3.0 | |
Internet Explorer | =3.2 | |
Internet Explorer | =4.0 | |
Internet Explorer | =4.0.1 | |
Internet Explorer | =4.1 | |
Internet Explorer | =5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0439 is considered a critical vulnerability as it allows unauthorized access to sensitive user cookies.
To fix CVE-2000-0439, users should upgrade to a later version of Internet Explorer that is not vulnerable to this issue.
CVE-2000-0439 affects Internet Explorer versions 3.0, 3.2, 4.0, 4.0.1, 4.1, and 5.0.
Using older versions of Internet Explorer is not safe as CVE-2000-0439 exposes users to potential cookie theft from malicious websites.
The risk associated with CVE-2000-0439 includes potential interception of sensitive data such as login credentials and session tokens.