Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7rjm-hcwm-8qgg

Опубликовано: 30 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

Mozilla 1.0 allows remote attackers to steal cookies from other domains via a javascript: URL with a leading "//" and ending in a newline, which causes the host/path check to fail.

Mozilla 1.0 allows remote attackers to steal cookies from other domains via a javascript: URL with a leading "//" and ending in a newline, which causes the host/path check to fail.

EPSS

Процентиль: 94%
0.12455
Средний

Дефекты

CWE-20

Связанные уязвимости

nvd
больше 22 лет назад

Mozilla 1.0 allows remote attackers to steal cookies from other domains via a javascript: URL with a leading "//" and ending in a newline, which causes the host/path check to fail.

EPSS

Процентиль: 94%
0.12455
Средний

Дефекты

CWE-20