CVE-2003-0594: High severity Mozilla Mozilla vulnerability
Mozilla allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Mozilla to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2003-0594?
CVE-2003-0594 is considered a moderate severity vulnerability as it allows for cookie access restrictions to be bypassed, potentially exposing sensitive information.
How do I fix CVE-2003-0594?
To fix CVE-2003-0594, users should upgrade to newer versions of Mozilla that address this vulnerability.
What versions of Mozilla are affected by CVE-2003-0594?
CVE-2003-0594 affects specific versions of Mozilla including 1.0, 1.1, 1.2, 1.3, 1.4, and their respective release candidates and betas.
Can CVE-2003-0594 lead to data leakage?
Yes, CVE-2003-0594 can lead to data leakage by allowing cookies to be sent outside of intended restrictions.
Is CVE-2003-0594 an issue for all Mozilla users?
CVE-2003-0594 specifically impacts users of older versions of Mozilla, making it crucial for those users to take action.