PT-2004-1639 · Kde · Kde Konqueror
Published
2004-06-08
·
Updated
2017-07-11
·
CVE-2004-0527
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
KDE Konqueror versions 2.1.1 through 2.2.2
Description
The issue allows remote attackers to spoof a legitimate URL in the status bar, facilitating a phishing attack. This is achieved by using A HREF tags with modified
alt values that point to the legitimate site, combined with an image map whose href points to the malicious site.Recommendations
For KDE Konqueror versions 2.1.1 through 2.2.2, consider disabling the use of image maps and modified
alt values in A HREF tags as a temporary workaround until a patch is available. Restrict access to untrusted websites to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kde Konqueror