CVE-2004-0866

3 documents3 sources
Severity
7.5HIGH
EPSS
3.5%
top 12.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 16
Latest updateApr 29

Description

Internet Explorer 6.0 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages5 packages

NVDmicrosoft/ie6.0
NVDkde/konqueror18 versions+17
NVDmozilla/firefox0.9.2
NVDsuse/suse_linux5 versions+4

Patches

🔴Vulnerability Details

2
GHSA
GHSA-8j48-wxgf-pfpq: Internet Explorer 62022-04-29
CVEList
CVE-2004-0866: Internet Explorer 62005-02-13
CVE-2004-0866 (HIGH CVSS 7.5) | Internet Explorer 6.0 allows web si | cvebase.io