CVE-2003-1492Link Following in Navigator

CWE-59Link Following3 documents3 sources
Severity
5.0MEDIUMNVD
EPSS
0.3%
top 50.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 31
Latest updateApr 29

Description

Netscape Navigator 7.0.2 and Mozilla allows remote attackers to access cookie information in a different domain via an HTTP request for a domain with an extra . (dot) at the end.

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-xwxc-wc23-rvj5: Netscape Navigator 72022-04-29
CVEList
CVE-2003-1492: Netscape Navigator 72007-10-24
CVE-2003-1492 — Link Following in Netscape Navigator | cvebase