First published: Mon Nov 26 2001(Updated: )
Internet Explorer 5.50.4134.0100 on Windows ME with "Prompt to allow cookies to be stored on your machine" enabled does not warn a user when a cookie is set using Javascript.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | =5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0919 is classified as a moderate severity vulnerability because it allows cookies to be set via JavaScript without user warning.
To fix CVE-2001-0919, consider upgrading to a later version of Internet Explorer that does not have this vulnerability.
CVE-2001-0919 affects users of Internet Explorer 5.5 on Windows ME with specific cookie settings enabled.
CVE-2001-0919 can facilitate attacks involving the unauthorized setting of cookies through JavaScript.
A potential workaround for CVE-2001-0919 is to disable JavaScript in the Internet Explorer settings.