CVE-2004-1527
Status: ModifiedMedium (5)—
Microsoft Internet Explorer 6.0 SP1 does not properly handle certain character strings in the Path attribute, which can cause it to modify cookies in other domains when the attacker's domain name is within the target's domain name or when wildcard DNS is being used, which allows remote attackers to hijack web sessions.
CVSS
- Version: 2.0
- Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N
- Base score: 5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 1.35%
- Percentile among all scored CVEs: 71
- Score date: 10/9/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.
CWEs
- NVD-CWE-Other
References
- http://marc.info/?l=bugtraq&m=110053968530613&w=2
- http://secunia.com/advisories/13208
- http://www.lac.co.jp/business/sns/intelligence/SNSadvisory_e/79_e.html
- http://www.securityfocus.com/bid/11680
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18073
- http://marc.info/?l=bugtraq&m=110053968530613&w=2
- http://secunia.com/advisories/13208
- http://www.lac.co.jp/business/sns/intelligence/SNSadvisory_e/79_e.html
- http://www.securityfocus.com/bid/11680
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18073
Raw JSON (NVD)
Show
{
"id": "CVE-2004-1527",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2004-12-31T05:00:00.000",
"references": [
{
"url": "http://marc.info/?l=bugtraq&m=110053968530613&w=2",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/13208",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.lac.co.jp/business/sns/intelligence/SNSadvisory_e/79_e.html",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/11680",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/18073",
"source": "cve@mitre.org"
},
{
"url": "http://marc.info/?l=bugtraq&m=110053968530613&w=2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/13208",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.lac.co.jp/business/sns/intelligence/SNSadvisory_e/79_e.html",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/11680",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/18073",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Microsoft Internet Explorer 6.0 SP1 does not properly handle certain character strings in the Path attribute, which can cause it to modify cookies in other domains when the attacker's domain name is within the target's domain name or when wildcard DNS is being used, which allows remote attackers to hijack web sessions."
}
],
"lastModified": "2026-06-16T22:07:53.100",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microsoft:ie:6.0:sp1:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "24DF2AB3-DEAB-4D70-986E-FFBB7E64B96A"
},
{
"criteria": "cpe:2.3:a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A19F6133-25D1-44A5-B6B9-354703436783"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}