CVE-1999-1087

HIGH
CVSS v3
7.5CVSS v2
11.77% EPSS (exploit probability)
CWE

Description

Internet Explorer 4 treats a 32-bit number ("dotless IP address") in the a URL as the hostname instead of an IP address, which causes IE to apply Local Intranet Zone settings to the resulting web page, allowing remote malicious web servers to conduct unauthorized activities by using URLs that contain the dotless IP address for their server.

Affected routers (1)

VendorModelMatched viaAffected versionsFixed inPatch Status
Ubiquiti Ubiquiti EdgeRouter 4 Likely Patched

External references