7.5

CVE-2004-1158

Exploit

Konqueror 3.x up to 3.2.2-6, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window or tab whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.

Data is provided by the National Vulnerability Database (NVD)
KdeKonqueror Version2.1.1
KdeKonqueror Version2.1.2
KdeKonqueror Version2.2.1
KdeKonqueror Version2.2.2
KdeKonqueror Version3.0
KdeKonqueror Version3.0.1
KdeKonqueror Version3.0.2
KdeKonqueror Version3.0.3
KdeKonqueror Version3.0.5
KdeKonqueror Version3.0.5b
KdeKonqueror Version3.1
KdeKonqueror Version3.1.1
KdeKonqueror Version3.1.2
KdeKonqueror Version3.1.3
KdeKonqueror Version3.1.4
KdeKonqueror Version3.1.5
KdeKonqueror Version3.2.1
KdeKonqueror Version3.2.2.6
KdeKonqueror Version3.2.3
KdeKonqueror Version3.3
KdeKonqueror Version3.3.1
KdeKonqueror Version3.3.2
MandrakesoftMandrake Linux Version10.0
MandrakesoftMandrake Linux Version10.0 Editionamd64
MandrakesoftMandrake Linux Version10.1
MandrakesoftMandrake Linux Version10.1 Editionx86_64
RedhatFedora Core Versioncore_2.0
RedhatFedora Core Versioncore_3.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 3.86% 0.871
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P