PT-2002-2186 · Netscape · Netscape Communicator
Published
2002-11-21
·
Updated
2008-09-10
·
CVE-2002-1204
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Netscape Communicator versions 4.x
Description:
The issue allows attackers to steal a user's preferences, including potentially sensitive information such as URL history, e-mail address, and possibly the e-mail password. This is achieved by redefining the
user pref() function and accessing the prefs.js file, which is stored in a directory with a predictable name.Recommendations:
For Netscape Communicator versions 4.x, consider restricting access to the
prefs.js file as a temporary workaround until a patch is available. Additionally, avoid using the user pref() function in sensitive contexts to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Netscape Communicator