{"api_version":"1","generated_at":"2026-07-23T10:08:52+00:00","cve":"CVE-1999-1235","urls":{"html":"https://cve.report/CVE-1999-1235","api":"https://cve.report/api/cve/CVE-1999-1235.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-1999-1235","nvd":"https://nvd.nist.gov/vuln/detail/CVE-1999-1235"},"summary":{"title":"CVE-1999-1235","description":"Internet Explorer 5.0 records the username and password for FTP servers in the URL history, which could allow (1) local users to read the information from another user's index.dat, or (2) people who are physically observing (\"shoulder surfing\") another user to read the information from the status bar when the user moves the mouse over a link.","state":"PUBLISHED","assigner":"mitre","published_at":"1999-08-25 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.6","severity":"","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","baseScore":4.6,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://ntbugtraq.ntadvice.com/default.asp?pid=36&sid=1&A2=ind9904&L=NTBUGTRAQ&P=R179","name":"http://ntbugtraq.ntadvice.com/default.asp?pid=36&sid=1&A2=ind9904&L=NTBUGTRAQ&P=R179","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"400"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/3289","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/3289","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://packetderm.cotse.com/mailing-lists/ntbugtraq/1999/0364.html","name":"http://packetderm.cotse.com/mailing-lists/ntbugtraq/1999/0364.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"NT Bugtraq Mailing List Archive: IE5 FTP password exposure &amp","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-1999-1235","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-1999-1235","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"1999","cve_id":"1235","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"5.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-01T17:02:53.918Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"19990825 IE5 FTP password exposure & index.dat null ACL problem","tags":["mailing-list","x_refsource_NTBUGTRAQ","x_transferred"],"url":"http://packetderm.cotse.com/mailing-lists/ntbugtraq/1999/0364.html"},{"name":"nt-ie5-user-ftp-password(3289)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/3289"},{"name":"19990331 Minor Bug in IE5.0","tags":["mailing-list","x_refsource_NTBUGTRAQ","x_transferred"],"url":"http://ntbugtraq.ntadvice.com/default.asp?pid=36&sid=1&A2=ind9904&L=NTBUGTRAQ&P=R179"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"1999-03-31T00:00:00.000Z","descriptions":[{"lang":"en","value":"Internet Explorer 5.0 records the username and password for FTP servers in the URL history, which could allow (1) local users to read the information from another user's index.dat, or (2) people who are physically observing (\"shoulder surfing\") another user to read the information from the status bar when the user moves the mouse over a link."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-12-18T21:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"19990825 IE5 FTP password exposure & index.dat null ACL problem","tags":["mailing-list","x_refsource_NTBUGTRAQ"],"url":"http://packetderm.cotse.com/mailing-lists/ntbugtraq/1999/0364.html"},{"name":"nt-ie5-user-ftp-password(3289)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/3289"},{"name":"19990331 Minor Bug in IE5.0","tags":["mailing-list","x_refsource_NTBUGTRAQ"],"url":"http://ntbugtraq.ntadvice.com/default.asp?pid=36&sid=1&A2=ind9904&L=NTBUGTRAQ&P=R179"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-1999-1235","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Internet Explorer 5.0 records the username and password for FTP servers in the URL history, which could allow (1) local users to read the information from another user's index.dat, or (2) people who are physically observing (\"shoulder surfing\") another user to read the information from the status bar when the user moves the mouse over a link."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"19990825 IE5 FTP password exposure & index.dat null ACL problem","refsource":"NTBUGTRAQ","url":"http://packetderm.cotse.com/mailing-lists/ntbugtraq/1999/0364.html"},{"name":"nt-ie5-user-ftp-password(3289)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/3289"},{"name":"19990331 Minor Bug in IE5.0","refsource":"NTBUGTRAQ","url":"http://ntbugtraq.ntadvice.com/default.asp?pid=36&sid=1&A2=ind9904&L=NTBUGTRAQ&P=R179"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-1999-1235","datePublished":"2001-09-12T04:00:00.000Z","dateReserved":"2001-08-31T00:00:00.000Z","dateUpdated":"2024-08-01T17:02:53.918Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"1999-08-25 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","baseScore":4.6,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":3.9,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:internet_explorer:5.0:*:*:*:*:*:*:*","matchCriteriaId":"E6B8985B-B927-4928-B1DB-18E29F796992"}]}]}]},"legacy_mitre":{"record":{"CveYear":"1999","CveId":"1235","Ordinal":"1","Title":"CVE-1999-1235","CVE":"CVE-1999-1235","Year":"1999"},"notes":[{"CveYear":"1999","CveId":"1235","Ordinal":"1","NoteData":"Internet Explorer 5.0 records the username and password for FTP servers in the URL history, which could allow (1) local users to read the information from another user's index.dat, or (2) people who are physically observing (\"shoulder surfing\") another user to read the information from the status bar when the user moves the mouse over a link.","Type":"Description","Title":"CVE-1999-1235"},{"CveYear":"1999","CveId":"1235","Ordinal":"2","NoteData":"2001-09-12","Type":"Other","Title":"Published"},{"CveYear":"1999","CveId":"1235","Ordinal":"3","NoteData":"2017-12-18","Type":"Other","Title":"Modified"}]}}}