CVE-2002-1151
 
Severity Score
7.5
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
The cross-site scripting protection for Konqueror in KDE 2.2.2 and 3.0 through 3.0.3 does not properly initialize the domains on sub-frames and sub-iframes, which can allow remote attackers to execute script and steal cookies from subframes that are in other domains.
La protección de ejecución de secuencias de comandos (scripts) en sitios cruzados en Konqueror 2.2.2 y 3.0 a 3.0.3 no inicializa adecuandamente los dominios en sub-marcos y sub-iframes (marcos incrustados), lo que puede permitir que atacantes remotos ejecuten comandos y roben cookies de submarcos que están en otros dominios.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2002-09-24 CVE Reserved
- 2002-10-11 CVE Published
- 2023-08-09 EPSS Updated
- 2024-08-08 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (11)
URL | Tag | Source |
---|---|---|
http://marc.info/?l=bugtraq&m=103175850925395&w=2 | Mailing List | |
http://www.kde.org/info/security/advisory-20020908-2.txt | X_refsource_confirm | |
http://www.osvdb.org/7867 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.debian.org/security/2002/dsa-167 | 2016-10-18 | |
http://www.securityfocus.com/bid/5689 | 2016-10-18 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Kde Search vendor "Kde" | Konqueror Search vendor "Kde" for product "Konqueror" | 2.2.2 Search vendor "Kde" for product "Konqueror" and version "2.2.2" | - |
Affected
| ||||||
Kde Search vendor "Kde" | Konqueror Search vendor "Kde" for product "Konqueror" | 3.0 Search vendor "Kde" for product "Konqueror" and version "3.0" | - |
Affected
| ||||||
Kde Search vendor "Kde" | Konqueror Search vendor "Kde" for product "Konqueror" | 3.0.1 Search vendor "Kde" for product "Konqueror" and version "3.0.1" | - |
Affected
| ||||||
Kde Search vendor "Kde" | Konqueror Search vendor "Kde" for product "Konqueror" | 3.0.2 Search vendor "Kde" for product "Konqueror" and version "3.0.2" | - |
Affected
| ||||||
Kde Search vendor "Kde" | Konqueror Search vendor "Kde" for product "Konqueror" | 3.0.3 Search vendor "Kde" for product "Konqueror" and version "3.0.3" | - |
Affected
| ||||||
Kde Search vendor "Kde" | Kde Search vendor "Kde" for product "Kde" | 2.2.2 Search vendor "Kde" for product "Kde" and version "2.2.2" | - |
Affected
| ||||||
Kde Search vendor "Kde" | Kde Search vendor "Kde" for product "Kde" | 3.0 Search vendor "Kde" for product "Kde" and version "3.0" | - |
Affected
| ||||||
Kde Search vendor "Kde" | Kde Search vendor "Kde" for product "Kde" | 3.0.1 Search vendor "Kde" for product "Kde" and version "3.0.1" | - |
Affected
| ||||||
Kde Search vendor "Kde" | Kde Search vendor "Kde" for product "Kde" | 3.0.2 Search vendor "Kde" for product "Kde" and version "3.0.2" | - |
Affected
| ||||||
Kde Search vendor "Kde" | Kde Search vendor "Kde" for product "Kde" | 3.0.3 Search vendor "Kde" for product "Kde" and version "3.0.3" | - |
Affected
|