Back

CVE-2001-0722

Internet Explorer 5.5 and 6.0 allows remote attackers to read and modify user cookies via Javascript in an about: URL, aka the "First Cookie Handling Vulnerability."

Published: Dec 6, 2001 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (2)

Vendor Product Version
microsoft internet_explorer 5.5
microsoft internet_explorer 6.0

GitHub Security Advisory GHSA-mm32-hgw5-cw3m

Internet Explorer 5.5 and 6.0 allows remote attackers to read and modify user cookies via...

Risk Scores

CVSS Score 6.4 / 10
EPSS Score 27.64%

Top 2% most likely to be exploited

Threat Score 33.9 / 100

Data Sources

NVD EPSS GitHub