CVE-2003-1560: Infoleak
Published Dec 31, 2003
·Updated
Netscape 4 sends Referer headers containing https:// URLs in requests for http:// URLs, which allows remote attackers to obtain potentially sensitive information by reading Referer log data.
Affected Software
1 affected component
Netscape Navigator=4
Event History
Dec 31, 2003
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityWeaknessAffected Software
Jul 15, 2008
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2003-1560?
CVE-2003-1560 is classified as a moderate severity vulnerability due to the potential exposure of sensitive information through Referer headers.
2
How do I fix CVE-2003-1560?
To mitigate CVE-2003-1560, users should upgrade from Netscape Navigator 4 to a more recent and secure browser.
3
What systems are affected by CVE-2003-1560?
CVE-2003-1560 specifically affects Netscape Navigator 4.
4
What is the impact of exploiting CVE-2003-1560?
Exploiting CVE-2003-1560 can allow remote attackers to access sensitive information through Referer log data.
5
Is there any workaround for CVE-2003-1560 if unable to upgrade?
A possible workaround for CVE-2003-1560 is to configure web servers to mask or not log Referer headers if using Netscape Navigator 4.