CVE-2003-0592

5 documents5 sources
Severity
7.5HIGH
EPSS
0.8%
top 25.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 15
Latest updateApr 29

Description

Konqueror in KDE 3.1.3 and earlier (kdelibs) allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Konqueror to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages2 packages

NVDkde/konqueror10 versions+9

Patches

🔴Vulnerability Details

2
GHSA
GHSA-x5c9-7pq8-8998: Konqueror in KDE 32022-04-29
CVEList
CVE-2003-0592: Konqueror in KDE 32004-03-16

📋Vendor Advisories

1
Red Hat
security flaw2004-03-10

💬Community

1
Bugzilla
CVE-2003-0592 security flaw2018-08-16
CVE-2003-0592 (HIGH CVSS 7.5) | Konqueror in KDE 3.1.3 and earlier | cvebase.io