Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2003-0459

Опубликовано: 27 авг. 2003
Источник: nvd
CVSS2: 5
EPSS Низкий

Описание

KDE Konqueror for KDE 3.1.2 and earlier does not remove authentication credentials from URLs of the "user:password@host" form in the HTTP-Referer header, which could allow remote web sites to steal the credentials for pages that link to the sites.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:kde:konqueror:2.1.1:*:*:*:*:*:*:*
cpe:2.3:a:kde:konqueror:2.2.2:*:*:*:*:*:*:*
cpe:2.3:a:kde:konqueror:3.0:*:*:*:*:*:*:*
cpe:2.3:a:kde:konqueror:3.0.1:*:*:*:*:*:*:*
cpe:2.3:a:kde:konqueror:3.0.2:*:*:*:*:*:*:*
cpe:2.3:a:kde:konqueror:3.0.3:*:*:*:*:*:*:*
cpe:2.3:a:kde:konqueror:3.0.5:*:*:*:*:*:*:*
cpe:2.3:a:kde:konqueror:3.1:*:*:*:*:*:*:*
cpe:2.3:a:kde:konqueror:3.1.1:*:*:*:*:*:*:*
cpe:2.3:a:kde:konqueror:3.1.2:*:*:*:*:*:*:*
cpe:2.3:a:kde:konqueror_embedded:0.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:analog_real-time_synthesizer:2.1.1-5:*:i386:*:*:*:*:*
cpe:2.3:a:redhat:analog_real-time_synthesizer:2.2-11:*:i386:*:*:*:*:*
cpe:2.3:a:redhat:analog_real-time_synthesizer:2.2-11:*:ia64:*:*:*:*:*
cpe:2.3:a:redhat:kdebase:3.0.3-13:*:i386:*:*:*:*:*
cpe:2.3:a:redhat:kdebase:3.0.3-13:*:i386_dev:*:*:*:*:*
cpe:2.3:a:redhat:kdelibs:2.1.1-5:*:i386:*:*:*:*:*
cpe:2.3:a:redhat:kdelibs:2.2-11:*:i386:*:*:*:*:*
cpe:2.3:a:redhat:kdelibs:2.2-11:*:ia64:*:*:*:*:*
cpe:2.3:a:redhat:kdelibs:3.0.0-10:*:i386:*:*:*:*:*
cpe:2.3:a:redhat:kdelibs:3.1-10:*:i386:*:*:*:*:*
cpe:2.3:a:redhat:kdelibs_devel:2.1.1-5:*:i386_dev:*:*:*:*:*
cpe:2.3:a:redhat:kdelibs_devel:2.2-11:*:i386_dev:*:*:*:*:*
cpe:2.3:a:redhat:kdelibs_devel:2.2-11:*:ia64_dev:*:*:*:*:*
cpe:2.3:a:redhat:kdelibs_devel:3.0.0-10:*:i386_dev:*:*:*:*:*
cpe:2.3:a:redhat:kdelibs_devel:3.0.3-8:*:i386_dev:*:*:*:*:*
cpe:2.3:a:redhat:kdelibs_devel:3.1-10:*:i386_dev:*:*:*:*:*
cpe:2.3:a:redhat:kdelibs_sound:2.1.1-5:*:i386_sound:*:*:*:*:*
cpe:2.3:a:redhat:kdelibs_sound:2.2-11:*:i386_sound:*:*:*:*:*
cpe:2.3:a:redhat:kdelibs_sound:2.2-11:*:ia64_sound:*:*:*:*:*
cpe:2.3:a:redhat:kdelibs_sound_devel:2.1.1-5:*:i386_sound_dev:*:*:*:*:*
cpe:2.3:a:redhat:kdelibs_sound_devel:2.2-11:*:i386_sound_dev:*:*:*:*:*
cpe:2.3:a:redhat:kdelibs_sound_devel:2.2-11:*:ia64_sound_dev:*:*:*:*:*

EPSS

Процентиль: 80%
0.01525
Низкий

5 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

ubuntu
почти 22 года назад

Описание отсутствует

redhat
почти 22 года назад

KDE Konqueror for KDE 3.1.2 and earlier does not remove authentication credentials from URLs of the "user:password@host" form in the HTTP-Referer header, which could allow remote web sites to steal the credentials for pages that link to the sites.

debian
почти 22 года назад

KDE Konqueror for KDE 3.1.2 and earlier does not remove authentication ...

github
около 3 лет назад

KDE Konqueror for KDE 3.1.2 and earlier does not remove authentication credentials from URLs of the "user:password@host" form in the HTTP-Referer header, which could allow remote web sites to steal the credentials for pages that link to the sites.

fstec
почти 22 года назад

Уязвимость операционной системы Red Hat Linux, позволяющая удаленному злоумышленнику нарушить конфиденциальность защищаемой информации

EPSS

Процентиль: 80%
0.01525
Низкий

5 Medium

CVSS2

Дефекты

NVD-CWE-Other