[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250038

 
 

909

 
 

195843

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2005-4685Date: (C)2005-12-31   (M)2023-12-22


Firefox and Mozilla can associate a cookie with multiple domains when the DNS resolver has a non-root domain in its search list, which allows remote attackers to trick a user into accepting a cookie for a hostname formed via search-list expansion of the hostname entered by the user, or steal a cookie for an expanded hostname, as demonstrated by an attacker who operates an ap1.com Internet web site to steal cookies associated with an ap1.com.example.com intranet web site.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 6.4
Exploit Score: 10.0
Impact Score: 4.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: NONE
  
Reference:
BID-15331
http://archives.neohapsis.com/archives/fulldisclosure/2005-11/0123.html
konqueror-cookie-information-disclosure(25291)

CPE    74
cpe:/a:mozilla:mozilla:1.1:beta
cpe:/a:mozilla:mozilla:1.4
cpe:/a:mozilla:mozilla:0.9.35
cpe:/a:mozilla:mozilla:1.3
...

© SecPod Technologies