PT-2003-2505 · Netscape · Netscape 4

Thor Larholm

·

Published

2003-12-31

·

Updated

2009-01-29

·

CVE-2003-1560

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Netscape 4
Description The issue allows remote attackers to obtain potentially sensitive information by reading Referer log data, as Netscape 4 sends Referer headers containing https:// URLs in requests for http:// URLs.
Recommendations For Netscape 4, consider disabling the sending of Referer headers or restricting access to Referer log data to minimize the risk of sensitive information disclosure.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2003-1560

Affected Products

Netscape 4