5

CVE-2002-2013

Exploit

Mozilla 0.9.6 and earlier and Netscape 6.2 and earlier allows remote attackers to steal cookies from another domain via a link with a hex-encoded null character (%00) followed by the target domain.

Data is provided by the National Vulnerability Database (NVD)
MozillaMozilla Version0.9.2
MozillaMozilla Version0.9.2.1
MozillaMozilla Version0.9.3
MozillaMozilla Version0.9.4
MozillaMozilla Version0.9.4.1
MozillaMozilla Version0.9.5
MozillaMozilla Version0.9.6
NetscapeCommunicator Version4.0
NetscapeCommunicator Version4.4
NetscapeCommunicator Version4.5
NetscapeCommunicator Version4.5_beta
NetscapeCommunicator Version4.06
NetscapeCommunicator Version4.6
NetscapeCommunicator Version4.07
NetscapeCommunicator Version4.7
NetscapeCommunicator Version4.08
NetscapeCommunicator Version4.51
NetscapeCommunicator Version4.61
NetscapeCommunicator Version4.72
NetscapeCommunicator Version4.73
NetscapeCommunicator Version4.74
NetscapeCommunicator Version4.75
NetscapeCommunicator Version4.76
NetscapeCommunicator Version4.77
NetscapeCommunicator Version4.78
NetscapeNavigator Version4.77
NetscapeNavigator Version6.0
NetscapeNavigator Version6.01
NetscapeNavigator Version6.1
NetscapeNavigator Version6.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.48% 0.621
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N