Description
Internet Explorer before 5.5 forwards cached user credentials for a secure web site to insecure pages on the same web site, which could allow remote attackers to obtain the credentials by monitoring connections to the web server, aka the "Cached Web Credentials" vulnerability.
References (4)
Core 4
Core References
Exploit, Patch, Vendor Advisory vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/1793
Various Sources x_refsource_misc
http://www.acrossecurity.com/aspr/ASPR-2000-07-22-2-PUB.txt
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/5367
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-076
Scores
EPSS
0.1261
EPSS Percentile
95.9%
Details
Status
published
Products (5)
microsoft/internet_explorer
4.0
microsoft/internet_explorer
4.0.1
microsoft/internet_explorer
4.1
microsoft/internet_explorer
5.0
microsoft/internet_explorer
5.01
Published
Dec 19, 2000
Tracked Since
Feb 18, 2026