5

CVE-2002-0354

The XMLHttpRequest object (XMLHTTP) in Netscape 6.1 and Mozilla 0.9.7 allows remote attackers to read arbitrary files and list directories on a client system by opening a URL that redirects the browser to the file on the client, then reading the result using the responseText property.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MozillaMozilla Version0.9.7
MozillaMozilla Version0.9.9
MozillaMozilla Version1.0 Updaterc1
MozillaMozilla Version1.0 Updaterc2
MozillaMozilla Version1.0 Updaterc3
NetscapeNavigator Version6.1
NetscapeNavigator Version6.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.38% 0.564
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N