First published: Tue Dec 31 2002(Updated: )
Mozilla 0.9.6 and earlier and Netscape 6.2 and earlier allows remote attackers to steal cookies from another domain via a link with a hex-encoded null character (%00) followed by the target domain.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Mozilla | =0.9.5 | |
Netscape Navigator | =6.2 | |
Netscape Communicator | =4.76 | |
Netscape Navigator | =6.0 | |
Netscape Communicator | =4.77 | |
Mozilla Mozilla | =0.9.3 | |
Netscape Communicator | =4.61 | |
Netscape Communicator | =4.07 | |
Netscape Communicator | =4.73 | |
Netscape Communicator | =4.51 | |
Netscape Communicator | =4.4 | |
Mozilla Mozilla | =0.9.2.1 | |
Netscape Communicator | =4.06 | |
Mozilla Mozilla | =0.9.2 | |
Netscape Communicator | =4.7 | |
Netscape Communicator | =4.78 | |
Netscape Communicator | =4.0 | |
Mozilla Mozilla | =0.9.4 | |
Netscape Communicator | =4.74 | |
Netscape Communicator | =4.08 | |
Netscape Communicator | =4.6 | |
Netscape Communicator | =4.5_beta | |
Netscape Navigator | =6.01 | |
Netscape Communicator | =4.72 | |
Mozilla Mozilla | =0.9.6 | |
Netscape Communicator | =4.5 | |
Mozilla Mozilla | =0.9.4.1 | |
Netscape Navigator | =6.1 | |
Netscape Navigator | =4.77 | |
Netscape Communicator | =4.75 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-2013 is considered a high-severity vulnerability due to its ability to steal cookies from other domains.
To mitigate CVE-2002-2013, upgrade to the latest version of Mozilla or Netscape that is not affected by this vulnerability.
CVE-2002-2013 affects Mozilla versions 0.9.6 and earlier.
Netscape Navigator versions 6.2 and earlier, as well as earlier versions of Netscape Communicator, are vulnerable to CVE-2002-2013.
CVE-2002-2013 allows remote attackers to exploit a cookie theft attack through a specially crafted link.