Internet Explorer 5.5 and 6.0 allows remote attackers to read and modify user cookies via Javascript in an about: URL, aka the "First Cookie Handling Vulnerability."
No PoCs from references.
- https://github.com/ARPSyndicate/cve-scores