Lucene search

K
cveMitreCVE-2003-1025
HistoryJan 20, 2004 - 5:00 a.m.

CVE-2003-1025

2004-01-2005:00:00
CWE-20
mitre
web.nvd.nist.gov
32
cve-2003-1025
internet explorer
url spoofing
vulnerability
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

7.4

Confidence

High

EPSS

0.974

Percentile

99.9%

Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a “%01” character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the “Improper URL Canonicalization Vulnerability.”

Affected configurations

Nvd
Node
microsoftinternet_explorerMatch6.0
VendorProductVersionCPE
microsoftinternet_explorer6.0cpe:2.3:a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:*

References

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

7.4

Confidence

High

EPSS

0.974

Percentile

99.9%