Back

CVE-2001-0665

Internet Explorer 6 and earlier allows remote attackers to cause certain HTTP requests to be automatically executed and appear to come from the user, which could allow attackers to gain privileges or execute operations within web-based services, aka the "HTTP Request Encoding vulnerability."

Published: Oct 30, 2001 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
microsoft ie *

GitHub Security Advisory GHSA-72jx-7mwq-4jpr

Internet Explorer 6 and earlier allows remote attackers to cause certain HTTP requests to be...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 12.09%

Top 4% most likely to be exploited

Threat Score 33.6 / 100

Data Sources

NVD EPSS GitHub