HIGH · 7.5

CVE-2000-0970

IIS 4.0 and 5.0 .ASP pages send the same Session ID cookie for secure and insecure web sessions, which could allow remote attackers to hijack the secure web session of the user if that user moves to a...

Vulnerability Description

IIS 4.0 and 5.0 .ASP pages send the same Session ID cookie for secure and insecure web sessions, which could allow remote attackers to hijack the secure web session of the user if that user moves to an insecure session, aka the "Session ID Cookie Marking" vulnerability.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
MicrosoftInternet Information Server4.0
MicrosoftInternet Information Services5.0

References

FAQ

What is CVE-2000-0970?

CVE-2000-0970 is a vulnerability with a CVSS score of 7.5 (HIGH). IIS 4.0 and 5.0 .ASP pages send the same Session ID cookie for secure and insecure web sessions, which could allow remote attackers to hijack the secure web session of the user if that user moves to a...

How severe is CVE-2000-0970?

CVE-2000-0970 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2000-0970?

Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Internet Information Server, Microsoft Internet Information Services.