VulnerabilityModified
CVE-2005-2830
Microsoft Internet Explorer 5.01, 5.5, and 6, when using an HTTPS proxy server that requires Basic Authentication, sends URLs in cleartext, which allows remote attackers to obtain sensitive information, aka "HTTPS Proxy Vulnerability."
MEDIUM 5.0EPSS 35.5%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 35.5%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Microsoft Internet Explorer 5.01, 5.5, and 6, when using an HTTPS proxy server that requires Basic Authentication, sends URLs in cleartext, which allows remote attackers to obtain sensitive information, aka "HTTPS Proxy Vulnerability."
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 35.49% probability · 98th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/ie · microsoft/internet explorer
- Source
- secure@microsoft.com
References
- http://secunia.com/advisories/15368
- http://secunia.com/advisories/18064
- http://secunia.com/advisories/18311
- http://securitytracker.com/id?1015350
- http://support.avaya.com/elmodocs2/security/ASA-2005-234.pdf
- http://www.securityfocus.com/bid/15825Patch
- http://www.vupen.com/english/advisories/2005/2867
- http://www.vupen.com/english/advisories/2005/2909
- http://www130.nortelnetworks.com/cgi-bin/eserv/cs/main.jsp?cscat=BLTNDETAIL&DocumentOID=375420
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-054
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23451
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1097
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1101
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1143
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1317
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1435
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1521
- http://secunia.com/advisories/15368
- http://secunia.com/advisories/18064
- http://secunia.com/advisories/18311
- http://securitytracker.com/id?1015350
- http://support.avaya.com/elmodocs2/security/ASA-2005-234.pdf
- http://www.securityfocus.com/bid/15825Patch
- http://www.vupen.com/english/advisories/2005/2867
- http://www.vupen.com/english/advisories/2005/2909
- http://www130.nortelnetworks.com/cgi-bin/eserv/cs/main.jsp?cscat=BLTNDETAIL&DocumentOID=375420
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-054
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23451
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1097
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1101
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.