Vulnerabilities > CVE-1999-1235 - Unspecified vulnerability in Microsoft Internet Explorer 5.0

047910
CVSS 4.6 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
local
low complexity
microsoft
exploit available

Summary

Internet Explorer 5.0 records the username and password for FTP servers in the URL history, which could allow (1) local users to read the information from another user's index.dat, or (2) people who are physically observing ("shoulder surfing") another user to read the information from the status bar when the user moves the mouse over a link.

Vulnerable Configurations

Part Description Count
Application
Microsoft
1

Exploit-Db

descriptionMicrosoft Internet Explorer 5.0 for Windows 2000/Windows NT 4 FTP Password Storage Vulnerability. CVE-1999-1235. Local exploit for windows platform
idEDB-ID:19473
last seen2016-02-02
modified1999-08-25
published1999-08-25
reporterMakoto Shiotsuki
sourcehttps://www.exploit-db.com/download/19473/
titleMicrosoft Internet Explorer 5.0 FTP Password Storage Vulnerability