CVE-1999-1235 EXPLOIT
4.6
MEDIUM · CVSS 2.0 · EPSS 2.7% (pctl 86)
Patch early
A public exploit exists.
Description
Internet Explorer 5.0 records the username and password for FTP servers in the URL history, which could allow (1) local users to read the information from another user's index.dat, or (2) people who are physically observing ("shoulder surfing") another user to read the information from the status bar when the user moves the mouse over a link.
Scoring
| CVSS | 4.6 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 2.71% — more likely to be exploited than 86% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 1999-08-25 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| microsoft | internet explorer |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft Internet Explorer 5 - FTP Password Storage | 1999-08-25 |
References
- http://ntbugtraq.ntadvice.com/default.asp?pid=36&sid=1&A2=ind9904&L=NTBUGTRAQ&P=R179
- http://packetderm.cotse.com/mailing-lists/ntbugtraq/1999/0364.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/3289
- http://ntbugtraq.ntadvice.com/default.asp?pid=36&sid=1&A2=ind9904&L=NTBUGTRAQ&P=R179
- http://packetderm.cotse.com/mailing-lists/ntbugtraq/1999/0364.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/3289
→ the Explorer · watch your stack · NVD