peter bassill · operator
$ cve CVE-2003-1025 JSON

CVE-2003-1025 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 26.9% (pctl 98)

Patch early

A public exploit exists.

Description

Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the "Improper URL Canonicalization Vulnerability."

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS26.91% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploityes
Published2004-01-20
Last modified2026-06-16

Affected (1)

VendorProduct
microsoftinternet explorer

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD