CVE-2003-1025

Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the "Improper URL Canonicalization Vulnerability."

Scoring

CVSS base score
2.57
EPSS probability
64.17%
Published
2004-01-06
Last modified
2026-03-16

Affected products

Markdown version · Browse all CVEs