CVE-2002-1186 describes an information disclosure vulnerability affecting Microsoft Internet Explorer versions 5.01 through 6.0. This flaw allows a remote attacker to steal sensitive user information by redirecting them to a malicious site, due to improper security checks on encoded URL characters. With a CVSS score of 5.0 (medium severity), it has a low attack complexity and requires no authentication, potentially leading to confidentiality breaches. Despite its age and a high FAUCET Risk Score, there is no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.0CPE matchmatch criteria | cpe:2.3:a:microsoft:ie:6.0:sp1:*:*:*:*:*:* | ||
5.0.1CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:5.0.1:*:*:*:*:*:*:* | ||
5.0.1CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp1:*:*:*:*:*:* | ||
5.0.1CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp2:*:*:*:*:*:* | ||
5.5CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:5.5:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.