peter bassill · operator
$ cve CVE-1999-1235 JSON

CVE-1999-1235 EXPLOIT

4.6
MEDIUM · CVSS 2.0 · EPSS 2.7% (pctl 86)

Patch early

A public exploit exists.

Description

Internet Explorer 5.0 records the username and password for FTP servers in the URL history, which could allow (1) local users to read the information from another user's index.dat, or (2) people who are physically observing ("shoulder surfing") another user to read the information from the status bar when the user moves the mouse over a link.

Scoring

CVSS4.6 (MEDIUM, v2.0)
VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
EPSS2.71% — more likely to be exploited than 86% of all CVEs
On CISA KEVno
Public exploityes
Published1999-08-25
Last modified2026-06-16

Affected (1)

VendorProduct
microsoftinternet explorer

Public exploits

SourceTitleDate
exploit-dbMicrosoft Internet Explorer 5 - FTP Password Storage1999-08-25

References

→ the Explorer  ·  watch your stack  ·  NVD