Netscape Communicator 4.x allows attackers to use a link to steal a user's preferences, including potentially sensitive information such as URL history, e-mail address, and possibly the e-mail password, by redefining the user_pref() function and accessing the prefs.js file, which is stored in a directory with a predictable name.
References
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:40
Type | Values Removed | Values Added |
---|---|---|
References | () http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0081.html - | |
References | () http://www.idefense.com/advisory/11.19.02c.txt - Vendor Advisory | |
References | () http://www.iss.net/security_center/static/10655.php - | |
References | () http://www.securityfocus.com/bid/6215 - |
Information
Published : 2002-11-29 05:00
Updated : 2024-11-20 23:40
NVD link : CVE-2002-1204
Mitre link : CVE-2002-1204
CVE.ORG link : CVE-2002-1204
JSON object : View
Products Affected
netscape
- communicator
CWE