CVE
- Id
- 5222
- CVE No.
- CVE-2002-0832
- Status
- Candidate
- Description
- Internet Explorer 5, 5.6, and 6 allows remote attackers to bypass cookie privacy settings and store information across browser sessions via the userData (storeuserData) feature.
- Phase
- Proposed (20020830)
- Votes
- ACCEPT(2) Baker, Foat | MODIFY(1) Frech | NOOP(3) Armstrong, Cole, Cox | REVIEWING(1) Wall
- Comments
- Foat> This is more an exposure than a vulnerability. IE does have, as the | autho0r contends, a "user data persistence" feature that is independent of the | settings used to control cookies. Microsoft allows a user to turn off the | feature via a simple setting. Bottom line, this is a configuration problem. | Frech> XF:ie-bypass-cookie-restrictions(10459)