{"api_version":"1","generated_at":"2026-07-23T06:57:06+00:00","cve":"CVE-2004-1527","urls":{"html":"https://cve.report/CVE-2004-1527","api":"https://cve.report/api/cve/CVE-2004-1527.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2004-1527","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2004-1527"},"summary":{"title":"CVE-2004-1527","description":"Microsoft Internet Explorer 6.0 SP1 does not properly handle certain character strings in the Path attribute, which can cause it to modify cookies in other domains when the attacker's domain name is within the target's domain name or when wildcard DNS is being used, which allows remote attackers to hijack web sessions.","state":"PUBLISHED","assigner":"mitre","published_at":"2004-12-31 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.lac.co.jp/business/sns/intelligence/SNSadvisory_e/79_e.html","name":"http://www.lac.co.jp/business/sns/intelligence/SNSadvisory_e/79_e.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"セキュリティ対策のラック｜情報を守るセキュリティ対策のパイオニア","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/13208","name":"http://secunia.com/advisories/13208","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Secunia - Advisories - Microsoft Internet Explorer Cookie Path Attribute Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/18073","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/18073","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=110053968530613&w=2","name":"http://marc.info/?l=bugtraq&m=110053968530613&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'[SNS Advisory No.79] A Possibility of Cookie Overwrite in' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/11680","name":"http://www.securityfocus.com/bid/11680","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Internet Explorer Cookie Overwrite Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2004-1527","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2004-1527","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2004","cve_id":"1527","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"ie","cpe6":"6.0","cpe7":"sp1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"1527","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"6.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T00:53:24.098Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.lac.co.jp/business/sns/intelligence/SNSadvisory_e/79_e.html"},{"name":"ie-path-cookie-overwrite(18073)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/18073"},{"name":"13208","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/13208"},{"name":"20041115 [SNS Advisory No.79] A Possibility of Cookie Overwrite in Microsoft Internet Explorer","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=110053968530613&w=2"},{"name":"11680","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/11680"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2004-11-15T00:00:00.000Z","descriptions":[{"lang":"en","value":"Microsoft Internet Explorer 6.0 SP1 does not properly handle certain character strings in the Path attribute, which can cause it to modify cookies in other domains when the attacker's domain name is within the target's domain name or when wildcard DNS is being used, which allows remote attackers to hijack web sessions."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_MISC"],"url":"http://www.lac.co.jp/business/sns/intelligence/SNSadvisory_e/79_e.html"},{"name":"ie-path-cookie-overwrite(18073)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/18073"},{"name":"13208","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/13208"},{"name":"20041115 [SNS Advisory No.79] A Possibility of Cookie Overwrite in Microsoft Internet Explorer","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=110053968530613&w=2"},{"name":"11680","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/11680"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2004-1527","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Microsoft Internet Explorer 6.0 SP1 does not properly handle certain character strings in the Path attribute, which can cause it to modify cookies in other domains when the attacker's domain name is within the target's domain name or when wildcard DNS is being used, which allows remote attackers to hijack web sessions."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.lac.co.jp/business/sns/intelligence/SNSadvisory_e/79_e.html","refsource":"MISC","url":"http://www.lac.co.jp/business/sns/intelligence/SNSadvisory_e/79_e.html"},{"name":"ie-path-cookie-overwrite(18073)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/18073"},{"name":"13208","refsource":"SECUNIA","url":"http://secunia.com/advisories/13208"},{"name":"20041115 [SNS Advisory No.79] A Possibility of Cookie Overwrite in Microsoft Internet Explorer","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=110053968530613&w=2"},{"name":"11680","refsource":"BID","url":"http://www.securityfocus.com/bid/11680"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2004-1527","datePublished":"2005-02-19T05:00:00.000Z","dateReserved":"2005-02-18T00:00:00.000Z","dateUpdated":"2024-08-08T00:53:24.098Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2004-12-31 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:a:microsoft:ie:6.0:sp1:*:*:*:*:*:*","matchCriteriaId":"24DF2AB3-DEAB-4D70-986E-FFBB7E64B96A"},{"vulnerable":false,"criteria":"cpe:2.3:a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:*","matchCriteriaId":"A19F6133-25D1-44A5-B6B9-354703436783"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2004","CveId":"1527","Ordinal":"1","Title":"CVE-2004-1527","CVE":"CVE-2004-1527","Year":"2004"},"notes":[{"CveYear":"2004","CveId":"1527","Ordinal":"1","NoteData":"Microsoft Internet Explorer 6.0 SP1 does not properly handle certain character strings in the Path attribute, which can cause it to modify cookies in other domains when the attacker's domain name is within the target's domain name or when wildcard DNS is being used, which allows remote attackers to hijack web sessions.","Type":"Description","Title":"CVE-2004-1527"},{"CveYear":"2004","CveId":"1527","Ordinal":"2","NoteData":"2005-02-19","Type":"Other","Title":"Published"},{"CveYear":"2004","CveId":"1527","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}