7.5
CVSSv2

CVE-2002-1151

Published: 11/10/2002 Updated: 18/10/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The cross-site scripting protection for Konqueror in KDE 2.2.2 and 3.0 up to and including 3.0.3 does not properly initialize the domains on sub-frames and sub-iframes, which can allow remote malicious users to execute script and steal cookies from subframes that are in other domains.

Vulnerable Product Search on Vulmon Subscribe to Product

kde konqueror 2.2.2

kde konqueror 3.0

kde konqueror 3.0.3

kde konqueror 3.0.1

kde konqueror 3.0.2

kde kde 2.2.2

kde kde 3.0

kde kde 3.0.1

kde kde 3.0.2

kde kde 3.0.3

Vendor Advisories

A cross site scripting problem has been discovered in Konqueror, a famous browser for KDE and other programs using KHTML The KDE team reports that Konqueror's cross site scripting protection fails to initialize the domains on sub-(i)frames correctly As a result, JavaScript is able to access any foreign subframe which is defined in the HTML source ...