PT-2002-1070 · Mozilla+1 · Netscape+4

Publicado

2002-06-18

·

Atualizado

2008-09-05

·

CVE-2002-0594

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions nautilus-devel versions 1.0.4 nautilus versions 1.0.4 nautilus-mozilla versions 1.0.4 Netscape version 6 Mozilla versions prior to 1.0 RC1
Description The issue allows remote attackers to determine the existence of files on the client system via a LINK element in a Cascading Style Sheet (CSS) page that causes an HTTP redirect. Exploitation of the vulnerabilities may lead to a violation of confidentiality, integrity, and availability of protected information. The exploitation can be carried out remotely.
Recommendations For nautilus-devel version 1.0.4, update to a version that contains a fix for this issue. For nautilus version 1.0.4, update to a version that contains a fix for this issue. For nautilus-mozilla version 1.0.4, update to a version that contains a fix for this issue. For Netscape version 6, update to a version that contains a fix for this issue. For Mozilla versions prior to 1.0 RC1, update to version 1.0 RC1 or later.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-08167
BDU:2015-08168
BDU:2015-08169
CVE-2002-0594

Produtos afetados

Mozilla Firefox
Netscape
Nautilus
Nautilus-Devel
Nautilus-Mozilla