Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2004-0869

Опубликовано: 16 сент. 2004
Источник: nvd
CVSS2: 5
EPSS Средний

Описание

Internet Explorer does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers to steal cookies and conduct unauthorized activities, aka "Cross Security Boundary Cookie Injection."

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:microsoft:ie:6:windows_server_2003_sp1:*:*:*:*:*:*

EPSS

Процентиль: 95%
0.20617
Средний

5 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

Internet Explorer does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers to steal cookies and conduct unauthorized activities, aka "Cross Security Boundary Cookie Injection."

EPSS

Процентиль: 95%
0.20617
Средний

5 Medium

CVSS2

Дефекты

NVD-CWE-Other