Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-394j-f4pf-g9c3

Опубликовано: 29 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

Mozilla allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Mozilla to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.

Mozilla allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Mozilla to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.

EPSS

Процентиль: 84%
0.02156
Низкий

Связанные уязвимости

redhat
почти 22 года назад

Mozilla allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Mozilla to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.

nvd
почти 22 года назад

Mozilla allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Mozilla to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.

debian
почти 22 года назад

Mozilla allows remote attackers to bypass intended cookie access restr ...

EPSS

Процентиль: 84%
0.02156
Низкий