CVE-2002-1186Sensitive Information Exposure in Microsoft Internet Explorer

3 documents3 sources
Severity
5.0MEDIUMNVD
EPSS
33.4%
top 3.07%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 11
Latest updateApr 30

Description

Internet Explorer 5.01 through 6.0 does not properly perform security checks on certain encoded characters within a URL, which allows a remote attacker to steal potentially sensitive information from a user by redirecting the user to another site that has that information, aka "Encoded Characters Information Disclosure."

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

NVDmicrosoft/internet_explorer5.0.1, 5.5, 6.0+2
NVDmicrosoft/ie6.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-m222-2mhj-3987: Internet Explorer 52022-04-30
CVEList
CVE-2002-1186: Internet Explorer 52004-09-01
CVE-2002-1186 — Sensitive Information Exposure | cvebase