CVE-2003-1559
medium · 5Microsoft Internet Explorer 5.22, and other 5 through 6 SP1 versions, sends Referer headers containing https:// URLs in requests for http:// URLs, which allows remote attackers to obtain potentially sensitive information by reading Referer log data.
5
CVSS
15.8%
EPSS (exploit prob.)
97th
EPSS percentile
2003-12-31
Published
AV:N/AC:L/Au:N/C:P/I:N/A:N
Weaknesses
CWE-200
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | ie | 5.22 |
| microsoft | internet_explorer | 5.5 |
| microsoft | internet_explorer | 6 |
| microsoft | internet_explorer | 6 |
Check a specific version with /api/v1/cve/match.
References
- http://securityreason.com/securityalert/3989
- http://www.gadgetopia.com/2003/12/23/OutlookWebAccessPrivacyHole.html
- http://www.securityfocus.com/archive/1/348360
- http://www.securityfocus.com/archive/1/348574
- http://www.securityfocus.com/bid/9295
- http://securityreason.com/securityalert/3989
- http://www.gadgetopia.com/2003/12/23/OutlookWebAccessPrivacyHole.html
- http://www.securityfocus.com/archive/1/348360
- http://www.securityfocus.com/archive/1/348574
- http://www.securityfocus.com/bid/9295
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2003-1559