First published: Tue Jun 18 2002(Updated: )
Netscape 6 and Mozilla 1.0 RC1 and earlier allows remote attackers to determine the existence of files on the client system via a LINK element in a Cascading Style Sheet (CSS) page that causes an HTTP redirect.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netscape Navigator | =6.2 | |
Netscape Navigator | =6.0 | |
Mozilla Mozilla | =1.0-rc1 | |
Netscape Navigator | =6.2.1 | |
Netscape Navigator | =6.01 | |
Netscape Navigator | =6.2.2 | |
Galeon Browser | =1.2 | |
Galeon Browser | =1.2.1 | |
Netscape Navigator | =6.1 | |
Mozilla Mozilla | =0.9.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0594 is classified as a medium severity vulnerability.
The recommended fix for CVE-2002-0594 is to update to a later version of Netscape Navigator or Mozilla that is not affected by this vulnerability.
CVE-2002-0594 exploits the ability to determine the existence of files on the client system via a LINK element in a CSS page causing an HTTP redirect.
CVE-2002-0594 affects Netscape Navigator 6.0 through 6.2.2 and Mozilla 1.0 RC1.
Yes, CVE-2002-0594 can potentially lead to unauthorized access by exposing file on the client system.