5

CVE-2002-2013

Exploit
Mozilla 0.9.6 and earlier and Netscape 6.2 and earlier allows remote attackers to steal cookies from another domain via a link with a hex-encoded null character (%00) followed by the target domain.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mozilla ≫ Mozilla Version 0.9.2
Mozilla ≫ Mozilla Version 0.9.2.1
Mozilla ≫ Mozilla Version 0.9.3
Mozilla ≫ Mozilla Version 0.9.4
Mozilla ≫ Mozilla Version 0.9.4.1
Mozilla ≫ Mozilla Version 0.9.5
Mozilla ≫ Mozilla Version 0.9.6
Netscape ≫ Communicator Version 4.0
Netscape ≫ Communicator Version 4.4
Netscape ≫ Communicator Version 4.5
Netscape ≫ Communicator Version 4.5_beta
Netscape ≫ Communicator Version 4.06
Netscape ≫ Communicator Version 4.6
Netscape ≫ Communicator Version 4.07
Netscape ≫ Communicator Version 4.7
Netscape ≫ Communicator Version 4.08
Netscape ≫ Communicator Version 4.51
Netscape ≫ Communicator Version 4.61
Netscape ≫ Communicator Version 4.72
Netscape ≫ Communicator Version 4.73
Netscape ≫ Communicator Version 4.74
Netscape ≫ Communicator Version 4.75
Netscape ≫ Communicator Version 4.76
Netscape ≫ Communicator Version 4.77
Netscape ≫ Communicator Version 4.78
Netscape ≫ Navigator Version 4.77
Netscape ≫ Navigator Version 6.0
Netscape ≫ Navigator Version 6.01
Netscape ≫ Navigator Version 6.1
Netscape ≫ Navigator Version 6.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.63% 0.731
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://alive.znep.com/~marcs/security/mozillacookie/demo.html
Exploit
http://archives.neohapsis.com/archives/bugtraq/2002-01/0270.html
Exploit
http://www.iss.net/security_center/static/7973.php
Patch
http://www.securityfocus.com/bid/3925
Patch