7.5

CVE-2002-1151

The cross-site scripting protection for Konqueror in KDE 2.2.2 and 3.0 through 3.0.3 does not properly initialize the domains on sub-frames and sub-iframes, which can allow remote attackers to execute script and steal cookies from subframes that are in other domains.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
KdeKonqueror Version2.2.2
KdeKonqueror Version3.0
KdeKonqueror Version3.0.1
KdeKonqueror Version3.0.2
KdeKonqueror Version3.0.3
KdeKde Version2.2.2
KdeKde Version3.0
KdeKde Version3.0.1
KdeKde Version3.0.2
KdeKde Version3.0.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.23% 0.866
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P