CVE-2003-1559
Published Dec 31, 2003
Last updated 3 years ago
Overview
- Description
- Microsoft Internet Explorer 5.22, and other 5 through 6 SP1 versions, sends Referer headers containing https:// URLs in requests for http:// URLs, which allows remote attackers to obtain potentially sensitive information by reading Referer log data.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-200
Evaluator
- Comment
- -
- Impact
- The only versions confirmed with this vulnerability are the ones listed in the CPE entry. Other IE Versions may, and probably are, affected but have not been confirmed yet.
- Solution
- The only versions confirmed with this vulnerability are the ones listed in the CPE entry. Other IE Versions may, and probably are, affected but have not been confirmed yet.
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:microsoft:ie:5.22:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "226A1B77-A80E-4ADE-8318-749CD1AD7CD0" }, { "criteria": "cpe:2.3:a:microsoft:internet_explorer:5.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "40F8042F-C621-45AE-9F8C-70469579643A" }, { "criteria": "cpe:2.3:a:microsoft:internet_explorer:6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "693D3C1C-E3E4-49DB-9A13-44ADDFF82507" }, { "criteria": "cpe:2.3:a:microsoft:internet_explorer:6:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D47247A3-7CD7-4D67-9D9B-A94A504DA1BE" } ], "operator": "OR" } ] } ]