CVE

Id
890  
CVE No.
CVE-1999-0910  
Status
Candidate  
Description
Microsoft Site Server and Commercial Internet System (MCIS) do not set an expiration for a cookie, which could then be cached by a proxy and inadvertently used by a different user.  
Phase
Proposed (19991208)  
Votes
ACCEPT(4) Baker, Ozancin, Prosser, Wall | MODIFY(2) Frech, Stracener | REJECT(1) Cole  
Comments
Frech> XF:siteserver-cis-cookie-cache | Cole> Whether cookies are a vulnerbality is a debate for another time, the | question here is whether the | expiration feature is a vulnerability and I do not think it is | because the underlying concerns for this | are present even without this feature. The expiration feature does | not add any new vulenrabilities | that are not already present with cookies. | Stracener> Add Ref: MSKB Q238647