CVE-2003-1559
Microsoft Internet Explorer 5.22, and other 5 through 6 SP1 versions, sends Referer headers containing https:// URLs in requests for http:// URLs, which allows remote attackers to obtain potentially sensitive information by reading Referer log data.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 15.8%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Microsoft Internet Explorer 5.22, and other 5 through 6 SP1 versions, sends Referer headers containing https:// URLs in requests for http:// URLs, which allows remote attackers to obtain potentially sensitive information by reading Referer log data.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 15.80% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- microsoft/ie · microsoft/internet explorer
- Source
- cve@mitre.org
References
- http://securityreason.com/securityalert/3989
- http://www.gadgetopia.com/2003/12/23/OutlookWebAccessPrivacyHole.html
- http://www.securityfocus.com/archive/1/348360
- http://www.securityfocus.com/archive/1/348574
- http://www.securityfocus.com/bid/9295
- http://securityreason.com/securityalert/3989
- http://www.gadgetopia.com/2003/12/23/OutlookWebAccessPrivacyHole.html
- http://www.securityfocus.com/archive/1/348360
- http://www.securityfocus.com/archive/1/348574
- http://www.securityfocus.com/bid/9295
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.