CVE-2000-0970
Internet Information Server 4.0 and 5.0 - Session ID Cookie Marking Vulnerability
Title source: llmDescription
IIS 4.0 and 5.0 .ASP pages send the same Session ID cookie for secure and insecure web sessions, which could allow remote attackers to hijack the secure web session of the user if that user moves to an insecure session, aka the "Session ID Cookie Marking" vulnerability.
References (4)
Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://www.osvdb.org/7265
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/5396
Various Sources x_refsource_misc
http://www.acrossecurity.com/aspr/ASPR-2000-07-22-1-PUB.txt
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-080
Scores
EPSS
0.4355
EPSS Percentile
98.6%
Details
Status
published
Products (2)
microsoft/internet_information_server
4.0
microsoft/internet_information_services
5.0
Published
Dec 19, 2000
Tracked Since
Feb 18, 2026