CVE-1999-0910
CVSS 2.0 Score 5.0 of 10 (medium)
Details
Summary
CVE-1999-0910 identifies a vulnerability in Microsoft Site Server and Commercial Internet System (MCIS). This issue arises due to MCIS failing to set an expiration date for cookies, making them susceptible to being cached by proxies and potentially used by unintended users. As a result, an attacker with access to a proxy server could gain unauthorized access to protected information or functionality. This security flaw can lead to serious privacy breaches and potential system compromises. It is recommended that affected organizations implement cookie security measures, such as setting expiration dates or using secure cookies, to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Microsoft