CVE-2001-0722: Medium severity Microsoft Internet Explorer vulnerability
Published Dec 6, 2001
·Updated
Internet Explorer 5.5 and 6.0 allows remote attackers to read and modify user cookies via Javascript in an about: URL, aka the "First Cookie Handling Vulnerability."
Affected Software
2 affected components
Microsoft Internet Explorer=5.5
Microsoft Internet Explorer=6.0
Remediation
Patch Available
Event History
Dec 6, 2001
CVE Published
05:00 AM
Mar 9, 2002
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0722?
CVE-2001-0722 is considered to have a medium severity due to the potential exploitation of user cookie information.
2
How do I fix CVE-2001-0722?
To fix CVE-2001-0722, users should upgrade to a newer version of Internet Explorer that does not have this vulnerability.
3
What versions of Internet Explorer are affected by CVE-2001-0722?
CVE-2001-0722 affects Internet Explorer versions 5.5 and 6.0 specifically.
4
What are the risks associated with CVE-2001-0722?
The risks include unauthorized access to user cookies, which can lead to session hijacking and other attacks.
5
What type of attack can exploit CVE-2001-0722?
CVE-2001-0722 can be exploited through JavaScript in about: URLs allowing attackers to read and modify cookies.