First published: Tue Dec 31 2002(Updated: )
Mozilla 1.0 allows remote attackers to steal cookies from other domains via a javascript: URL with a leading "//" and ending in a newline, which causes the host/path check to fail.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2002-2314 is considered to be moderate as it allows remote attackers to steal cookies.
To fix CVE-2002-2314, upgrade to a later version of Mozilla that is not vulnerable to this issue.
CVE-2002-2314 describes a cross-site scripting vulnerability that allows cookie theft.
CVE-2002-2314 specifically affects Mozilla version 1.0.
Yes, CVE-2002-2314 can significantly affect user privacy by allowing attackers to access sensitive cookie data.