PT-2003-2437 · Mozilla+1 · Mozilla Firefox+1

Publicado

2003-12-31

·

Atualizado

2024-03-12

·

CVE-2003-1492

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Netscape Navigator version 7.0.2 Mozilla (affected versions not specified)
Description The issue allows remote attackers to access cookie information in a different domain via an HTTP request for a domain with an extra . (dot) at the end.
Recommendations For Netscape Navigator version 7.0.2, update to a version that fixes this issue. For Mozilla, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Link Following

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2003-1492
ROSA-SA-2024-2370

Produtos afetados

Mozilla Firefox
Netscape Navigator