7.5

CVE-2003-0594

Exploit

Mozilla allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Mozilla to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.

Data is provided by the National Vulnerability Database (NVD)
MozillaMozilla Version1.0
MozillaMozilla Version1.0 Updaterc1
MozillaMozilla Version1.0 Updaterc2
MozillaMozilla Version1.0.1
MozillaMozilla Version1.0.2
MozillaMozilla Version1.1
MozillaMozilla Version1.1 Updatealpha
MozillaMozilla Version1.1 Updatebeta
MozillaMozilla Version1.2
MozillaMozilla Version1.2 Updatealpha
MozillaMozilla Version1.2 Updatebeta
MozillaMozilla Version1.2.1
MozillaMozilla Version1.3
MozillaMozilla Version1.3.1
MozillaMozilla Version1.4
MozillaMozilla Version1.4.1
MozillaMozilla Version1.4.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.52% 0.642
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P