CVE-2000-0970
N/A
N/A
Summary
IIS 4.0 and 5.0 .ASP pages send the same Session ID cookie for secure and insecure web sessions, which could allow remote attackers to hijack the secure web session of the user if that user moves to an insecure session, aka the "Session ID Cookie Marking" vulnerability.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www.osvdb.org/7265
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5396
- http://www.acrossecurity.com/aspr/ASPR-2000-07-22-1-PUB.txt
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-080
References
- http://www.osvdb.org/7265
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5396
- http://www.acrossecurity.com/aspr/ASPR-2000-07-22-1-PUB.txt
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-080
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.