4.6
CVSSv2

CVE-1999-1235

Published: 25/08/1999 Updated: 22/07/2021
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 465
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Internet Explorer 5.0 records the username and password for FTP servers in the URL history, which could allow (1) local users to read the information from another user's index.dat, or (2) people who are physically observing ("shoulder surfing") another user to read the information from the status bar when the user moves the mouse over a link.

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft internet explorer 5.0

Exploits

Microsoft Internet Explorer 50 for Windows 2000/Windows NT 4 FTP Password Storage Vulnerability source: wwwsecurityfocuscom/bid/610/info FTP usernames and passwords for sites accessed via Internet Explorer 5X are stored (cleartext) in history files stored under \Winnt\Profiles\[Username]\History\HistoryIE5\indexdat and \Winnt\Profile ...