Description
Internet Explorer 4 treats a 32-bit number ("dotless IP address") in the a URL as the hostname instead of an IP address, which causes IE to apply Local Intranet Zone settings to the resulting web page, allowing remote malicious web servers to conduct unauthorized activities by using URLs that contain the dotless IP address for their server.
References (5)
Core 5
Core References
Vendor Advisory x_refsource_confirm
http://www.microsoft.com/Windows/Ie/security/dotless.asp
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://www.osvdb.org/7828
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/1998/ms98-016
Patch, Vendor Advisory vendor-advisory
x_refsource_mskb
http://support.microsoft.com/support/kb/articles/q168/6/17.asp
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/2209
Scores
EPSS
0.0628
EPSS Percentile
92.9%
Details
Status
published
Products (2)
microsoft/internet_explorer
4.0
microsoft/internet_explorer
4.0.1 (2 CPE variants)
Published
Dec 31, 1999
Tracked Since
Feb 18, 2026