VYPR
Unrated severityNVD Advisory· Published Dec 31, 2004· Updated Apr 16, 2026

CVE-2004-1527

CVE-2004-1527

Description

Microsoft Internet Explorer 6.0 SP1 improperly validates Path attribute in cookies, allowing attackers to overwrite cookies from other domains and hijack web sessions.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Microsoft Internet Explorer 6.0 SP1 improperly validates Path attribute in cookies, allowing attackers to overwrite cookies from other domains and hijack web sessions.

Vulnerability

Microsoft Internet Explorer 6.0 Service Pack 1 contains a vulnerability in its cookie handling logic. The browser fails to properly validate certain character strings in the Path attribute when accepting cookies. This allows an attacker to craft a cookie with a Path attribute that, under specific conditions, can overwrite a cookie issued by a different domain. The affected version is Internet Explorer 6.0 SP1 [2].

Exploitation

An attacker must be able to send a crafted cookie to a victim's browser. Two preconditions facilitate exploitation: (1) the attacker's domain name is contained within the target's domain name, or (2) the target site uses wildcard DNS, causing the attacker's IP address to be contained within the target's IP address. Once these conditions are met, the attacker can set a cookie with a crafted Path attribute that overwrites the legitimate cookie of the target domain, effectively hijacking the session [2].

Impact

Successful exploitation allows the attacker to overwrite cookies belonging to another domain. This can lead to session hijacking, enabling the attacker to impersonate a legitimate user and gain unauthorized access to web applications and services [2].

Mitigation

Microsoft addressed this vulnerability in Windows XP Service Pack 2. Users unable to upgrade can configure Internet Explorer to prompt before accepting cookies: navigate to Internet Options > Privacy > Advanced, check "Override automatic cookie handling", set First-party Cookies to "Prompt", and click OK [2].

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.