CVE Vulnerabilities

CVE-2002-1151

Published: Oct 11, 2002 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The cross-site scripting protection for Konqueror in KDE 2.2.2 and 3.0 through 3.0.3 does not properly initialize the domains on sub-frames and sub-iframes, which can allow remote attackers to execute script and steal cookies from subframes that are in other domains.

Affected Software

NameVendorStart VersionEnd Version
KonquerorKde2.2.2 (including)2.2.2 (including)
KonquerorKde3.0 (including)3.0 (including)
KonquerorKde3.0.1 (including)3.0.1 (including)
KonquerorKde3.0.2 (including)3.0.2 (including)
KonquerorKde3.0.3 (including)3.0.3 (including)
Red Hat Enterprise Linux AS (Advanced Server) version 2.1RedHat*
Red Hat Linux 7.2RedHat*
Red Hat Linux 7.3RedHat*
Red Hat Linux 8.0RedHat*

References