CVE Vulnerabilities

CVE-2003-0592

Published: Apr 15, 2004 | Modified: Oct 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Konqueror in KDE 3.1.3 and earlier (kdelibs) allows remote attackers to bypass intended cookie access restrictions on a web application via %2e%2e (encoded dot dot) directory traversal sequences in a URL, which causes Konqueror to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.

Affected Software

Name Vendor Start Version End Version
Konqueror Kde 2.1.1 (including) 2.1.1 (including)
Konqueror Kde 2.2.2 (including) 2.2.2 (including)
Konqueror Kde 3.0 (including) 3.0 (including)
Konqueror Kde 3.0.1 (including) 3.0.1 (including)
Konqueror Kde 3.0.2 (including) 3.0.2 (including)
Konqueror Kde 3.0.3 (including) 3.0.3 (including)
Konqueror Kde 3.0.5 (including) 3.0.5 (including)
Konqueror Kde 3.1 (including) 3.1 (including)
Konqueror Kde 3.1.1 (including) 3.1.1 (including)
Konqueror Kde 3.1.2 (including) 3.1.2 (including)
Konqueror_embedded Kde 0.1 (including) 0.1 (including)
Red Hat Enterprise Linux AS (Advanced Server) version 2.1 RedHat *
Red Hat Enterprise Linux ES version 2.1 RedHat *
Red Hat Enterprise Linux WS version 2.1 RedHat *
Red Hat Linux 9 RedHat *
Red Hat Linux Advanced Workstation 2.1 RedHat *

References