Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2002-1204

Опубликовано: 29 нояб. 2002
Источник: nvd
CVSS2: 5
EPSS Низкий

Описание

Netscape Communicator 4.x allows attackers to use a link to steal a user's preferences, including potentially sensitive information such as URL history, e-mail address, and possibly the e-mail password, by redefining the user_pref() function and accessing the prefs.js file, which is stored in a directory with a predictable name.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:netscape:communicator:4.6:*:*:*:*:*:*:*
cpe:2.3:a:netscape:communicator:4.7:*:*:*:*:*:*:*
cpe:2.3:a:netscape:communicator:4.61:*:*:*:*:*:*:*
cpe:2.3:a:netscape:communicator:4.72:*:*:*:*:*:*:*
cpe:2.3:a:netscape:communicator:4.73:*:*:*:*:*:*:*
cpe:2.3:a:netscape:communicator:4.74:*:*:*:*:*:*:*
cpe:2.3:a:netscape:communicator:4.75:*:*:*:*:*:*:*
cpe:2.3:a:netscape:communicator:4.76:*:*:*:*:*:*:*
cpe:2.3:a:netscape:communicator:4.77:*:*:*:*:*:*:*
cpe:2.3:a:netscape:communicator:4.78:*:*:*:*:*:*:*

EPSS

Процентиль: 74%
0.00852
Низкий

5 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
больше 3 лет назад

Netscape Communicator 4.x allows attackers to use a link to steal a user's preferences, including potentially sensitive information such as URL history, e-mail address, and possibly the e-mail password, by redefining the user_pref() function and accessing the prefs.js file, which is stored in a directory with a predictable name.

EPSS

Процентиль: 74%
0.00852
Низкий

5 Medium

CVSS2

Дефекты

NVD-CWE-Other