CVE-1999-0347

Internet Explorer 4.01 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-1999-0347. PoCs published by Georgi Guninski.

AI-analyzed exploit summary This is a vulnerability writeup describing a cross-frame security bypass in Internet Explorer 4.x and 5.5, allowing arbitrary code execution via malformed URLs with '%01' or equivalent characters. No actual exploit code is provided.

Description

Internet Explorer 4.01 allows remote attackers to read local files and spoof web pages via a "%01" character in an "about:" Javascript URL, which causes Internet Explorer to use the domain specified after the character.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Georgi Guninski · textremotewindows
https://www.exploit-db.com/exploits/19156

This is a vulnerability writeup describing a cross-frame security bypass in Internet Explorer 4.x and 5.5, allowing arbitrary code execution via malformed URLs with '%01' or equivalent characters. No actual exploit code is provided.

Classification
Writeup 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Microsoft Internet Explorer 4.x, 5.5
No auth needed
Prerequisites: Victim must visit a malicious webpage or open a malicious HTML email
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=91745430007021&w=2
Mailing List mailing-list x_refsource_ntbugtraq
http://marc.info/?l=ntbugtraq&m=91756771207719&w=2

Scores

EPSS 0.0746
EPSS Percentile 93.7%

Details

Status published
Published Jan 26, 1999
Tracked Since Feb 18, 2026