7.5
CVE-2000-0970
- EPSS 45.66%
- Veröffentlicht 19.12.2000 05:00:00
- Zuletzt bearbeitet 23.09.2026 10:10:00
- Erkennungen
IIS 4.0 and 5.0 .ASP pages send the same Session ID cookie for secure and insecure web sessions, which could allow remote attackers to hijack the secure web session of the user if that user moves to an insecure session, aka the "Session ID Cookie Marking" vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Internet Information Server Version 4.0
Microsoft ≫ Internet Information Services Version 5.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 45.66% | 0.987 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://www.osvdb.org/7265
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-080
https://exchange.xforce.ibmcloud.com/vulnerabilities/5396
http://www.acrossecurity.com/aspr/ASPR-2000-07-22-1-PUB.txt