CVE Vulnerabilities

CVE-2004-0870

Published: Sep 16, 2004 | Modified: Jul 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

KDE Konqueror does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers to steal cookies and conduct unauthorized activities, aka Cross Security Boundary Cookie Injection.

Affected Software

Name Vendor Start Version End Version
Konqueror Kde 2.1.1 (including) 2.1.1 (including)
Konqueror Kde 2.1.2 (including) 2.1.2 (including)
Konqueror Kde 2.2.1 (including) 2.2.1 (including)
Konqueror Kde 2.2.2 (including) 2.2.2 (including)
Konqueror Kde 3.0 (including) 3.0 (including)
Konqueror Kde 3.0.1 (including) 3.0.1 (including)
Konqueror Kde 3.0.2 (including) 3.0.2 (including)
Konqueror Kde 3.0.3 (including) 3.0.3 (including)
Konqueror Kde 3.0.5 (including) 3.0.5 (including)
Konqueror Kde 3.0.5b (including) 3.0.5b (including)
Konqueror Kde 3.1 (including) 3.1 (including)
Konqueror Kde 3.1.1 (including) 3.1.1 (including)
Konqueror Kde 3.1.2 (including) 3.1.2 (including)
Konqueror Kde 3.1.3 (including) 3.1.3 (including)
Konqueror Kde 3.1.4 (including) 3.1.4 (including)
Konqueror Kde 3.1.5 (including) 3.1.5 (including)
Konqueror Kde 3.2.1 (including) 3.2.1 (including)
Konqueror Kde 3.2.3 (including) 3.2.3 (including)

References