CVE-2002-2314

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
31/12/2002
Last modified:
05/09/2008

Description

Mozilla 1.0 allows remote attackers to steal cookies from other domains via a javascript: URL with a leading "//" and ending in a newline, which causes the host/path check to fail.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mozilla:mozilla:1.0:*:*:*:*:*:*:*