CVE Vulnerabilities

CVE-2003-0594

Published: Apr 15, 2004 | Modified: Oct 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Mozilla allows remote attackers to bypass intended cookie access restrictions on a web application via %2e%2e (encoded dot dot) directory traversal sequences in a URL, which causes Mozilla to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.

Affected Software

Name Vendor Start Version End Version
Mozilla Mozilla 1.0 (including) 1.0 (including)
Mozilla Mozilla 1.0-rc1 (including) 1.0-rc1 (including)
Mozilla Mozilla 1.0-rc2 (including) 1.0-rc2 (including)
Mozilla Mozilla 1.0.1 (including) 1.0.1 (including)
Mozilla Mozilla 1.0.2 (including) 1.0.2 (including)
Mozilla Mozilla 1.1 (including) 1.1 (including)
Mozilla Mozilla 1.1-alpha (including) 1.1-alpha (including)
Mozilla Mozilla 1.1-beta (including) 1.1-beta (including)
Mozilla Mozilla 1.2 (including) 1.2 (including)
Mozilla Mozilla 1.2-alpha (including) 1.2-alpha (including)
Mozilla Mozilla 1.2-beta (including) 1.2-beta (including)
Mozilla Mozilla 1.2.1 (including) 1.2.1 (including)
Mozilla Mozilla 1.3 (including) 1.3 (including)
Mozilla Mozilla 1.3.1 (including) 1.3.1 (including)
Mozilla Mozilla 1.4 (including) 1.4 (including)
Mozilla Mozilla 1.4.1 (including) 1.4.1 (including)
Mozilla Mozilla 1.4.2 (including) 1.4.2 (including)

References