CVE Vulnerabilities

CVE-2002-1151

Published: Oct 11, 2002 | Modified: Oct 18, 2016
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The cross-site scripting protection for Konqueror in KDE 2.2.2 and 3.0 through 3.0.3 does not properly initialize the domains on sub-frames and sub-iframes, which can allow remote attackers to execute script and steal cookies from subframes that are in other domains.

Affected Software

Name Vendor Start Version End Version
Konqueror Kde 2.2.2 (including) 2.2.2 (including)
Konqueror Kde 3.0 (including) 3.0 (including)
Konqueror Kde 3.0.1 (including) 3.0.1 (including)
Konqueror Kde 3.0.2 (including) 3.0.2 (including)
Konqueror Kde 3.0.3 (including) 3.0.3 (including)

References