Vulnerability Name: | CCN-2275 | ||||||
Published: | 1999-06-06 | ||||||
Updated: | 1999-06-06 | ||||||
Summary: | A vulnerability in the 'data:' protocol in Netscape Communicator allows windows to sniff the URLs navigated in other windows. Normally the ability to do this is disallowed, but using find lets malicious Web pages subvert this security mechanism. | ||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||
CVSS v2 Severity: | 2.1 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
| ||||||
Vulnerability Consequences: | Obtain Information | ||||||
References: | Source: CCN Type: BugTraq Mailing List, 1999-06-06 10:17:04 Netscape Communicator code injection in JavaScript console using "data:" protocol Source: CCN Type: Georgi Guninski Vulnerability Demonstration Netscape Communicator code injection in JavaScript console using "data:" protocol ver. 4.6 and below Source: CCN Type: BID-836 Netscape Communicator Javascript Sniffing Vulnerability Source: XF Type: UNKNOWN ns-datatrack(2275) | ||||||
Vulnerable Configuration: | Configuration CCN 1:![]() | ||||||
BACK |