First published: Fri Jul 23 2004(Updated: )
Konqueror 3.1.3, 3.2.2, and possibly other versions does not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
KDE Konqueror | =3.1.3 | |
KDE Konqueror | =3.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0721 is considered a medium severity vulnerability due to its potential for web site spoofing and content injection.
To fix CVE-2004-0721, upgrade to a patched version of Konqueror that addresses this frame injection vulnerability.
CVE-2004-0721 affects Konqueror versions 3.1.3, 3.2.2, and potentially other earlier versions.
CVE-2004-0721 can facilitate attacks such as web site spoofing and cross-domain content injection.
Yes, CVE-2004-0721 specifically affects the Konqueror web browser.