Required CVE Record Information
Description
The cross-site scripting protection for Konqueror in KDE 2.2.2 and 3.0 through 3.0.3 does not properly initialize the domains on sub-frames and sub-iframes, which can allow remote attackers to execute script and steal cookies from subframes that are in other domains.
References 11 Total
- redhat.com: RHSA-2002:220 vendor-advisory
- http://www.kde.org/info/security/advisory-20020908-2.txt
- iss.net: ie-sameoriginpolicy-bypass(10039) vdb-entry
- linux-mandrake.com: MDKSA-2002:064 vendor-advisory
- debian.org: DSA-167 vendor-advisory
- redhat.com: RHSA-2002:221 vendor-advisory
- distro.conectiva.com.br: CLA-2002:525 vendor-advisory
- securityfocus.com: 5689 vdb-entry
- osvdb.org: 7867 vdb-entry
- ftp.caldera.com: CSSA-2002-047.0 vendor-advisory
- marc.info: 20020910 KDE Security Advisory: Konqueror Cross Site Scripting Vulnerability mailing-list
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 11 Total
- redhat.com: RHSA-2002:220 vendor-advisoryx_transferred
- http://www.kde.org/info/security/advisory-20020908-2.txt x_transferred
- iss.net: ie-sameoriginpolicy-bypass(10039) vdb-entryx_transferred
- linux-mandrake.com: MDKSA-2002:064 vendor-advisoryx_transferred
- debian.org: DSA-167 vendor-advisoryx_transferred
- redhat.com: RHSA-2002:221 vendor-advisoryx_transferred
- distro.conectiva.com.br: CLA-2002:525 vendor-advisoryx_transferred
- securityfocus.com: 5689 vdb-entryx_transferred
- osvdb.org: 7867 vdb-entryx_transferred
- ftp.caldera.com: CSSA-2002-047.0 vendor-advisoryx_transferred
- marc.info: 20020910 KDE Security Advisory: Konqueror Cross Site Scripting Vulnerability mailing-listx_transferred