CVE-2003-1025

Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the "Improper URL Canonicalization Vulnerability."
Configurations

Configuration 1 (hide)

cpe:2.3:a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:*

History

23 Jul 2021, 12:55

Type Values Removed Values Added
CPE cpe:2.3:a:microsoft:ie:6.0:*:*:*:*:*:*:* cpe:2.3:a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:*

Information

Published : 2004-01-20 05:00

Updated : 2023-12-10 10:17


NVD link : CVE-2003-1025

Mitre link : CVE-2003-1025

CVE.ORG link : CVE-2003-1025


JSON object : View

Products Affected

microsoft

  • internet_explorer
CWE
CWE-20

Improper Input Validation