CVE Database
/

CVE-2002-1186

Back to search

CVE-2002-1186

Published: Sep 1, 2004

Modified: Aug 8, 2024

PUBLISHED

Description

Internet Explorer 5.01 through 6.0 does not properly perform security checks on certain encoded characters within a URL, which allows a remote attacker to steal potentially sensitive information from a user by redirecting the user to another site that has that information, aka "Encoded Characters Information Disclosure."

VendorProductVersions

n/a

n/a

affected
n/a

References

MS02-066
vendor-advisory
x_refsource_MS
5610
vdb-entry
x_refsource_BID
ie-sameoriginpolicy-bypass(10039)
vdb-entry
x_refsource_XF
7845
vdb-entry
x_refsource_OSVDB
oval:org.mitre.oval:def:495
vdb-entry
signature
x_refsource_OVAL
oval:org.mitre.oval:def:471
vdb-entry
signature
x_refsource_OVAL
oval:org.mitre.oval:def:143
vdb-entry
signature
x_refsource_OVAL

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now