Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2002-1204

Overview

Vulnerability Score 5.0 5.0
CVE Id CVE-2002-1204
Last Modified 10 Sep 2008 03:14:03
Published 29 Nov 2002 12:00:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2002-1204

Summary

Netscape Communicator 4.x allows attackers to use a link to steal a user's preferences, including potentially sensitive information such as URL history, e-mail address, and possibly the e-mail password, by redefining the user_pref() function and accessing the prefs.js file, which is stored in a directory with a predictable name.

Vulnerable Systems

Application

  • Netscape Communicator 4.6

  • Netscape Communicator 4.61

  • Netscape Communicator 4.7

  • Netscape Communicator 4.72

  • Netscape Communicator 4.73

  • Netscape Communicator 4.74

  • Netscape Communicator 4.75

  • Netscape Communicator 4.76

  • Netscape Communicator 4.77

  • Netscape Communicator 4.78


References

BID - 6215

XF - netscape-preferences-file(10655)

MISC - http://www.idefense.com/advisory/11.19.02c.txt

VULNWATCH - 20021119 iDEFENSE Security Advisory 11.19.02c: Netscape Predictable Directory Structure Allows Theft of Preferences File


Last Updated: 27 May 2016 10:37:14