PT-2002-2610 · Commonname · Commonname Toolbar

Published

2002-12-31

·

Updated

2008-09-05

·

CVE-2002-1888

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions CommonName Toolbar version 3.5.2.0
Description The issue concerns the CommonName Toolbar sending unqualified domain name requests to the CommonName organization and possibly other web servers for name resolution. This allows those organizations to obtain internal server names.
Recommendations For CommonName Toolbar version 3.5.2.0, consider restricting access to internal server names to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1888

Affected Products

Commonname Toolbar