Vulnerability Name:

CVE-2002-0815 (CCN-9726)

Assigned:2002-07-29
Published:2002-07-29
Updated:2021-07-23
Summary:The Javascript "Same Origin Policy" (SOP), as implemented in (1) Netscape, (2) Mozilla, and (3) Internet Explorer, allows a remote web server to access HTTP and SOAP/XML content from restricted sites by mapping the malicious server's parent DNS domain name to the restricted site, loading a page from the restricted site into one frame, and passing the information to the attacker-controlled frame, which is allowed because the document.domain of the two frames matches on the parent domain.
CVSS v3 Severity:7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-Other
Vulnerability Consequences:Bypass Security
References:Source: CCN
Type: BugTraq Mailing List, Mon Jul 29 2002 - 12:57:11 CDT
XWT Foundation Advisory: Firewall circumvention possible with all browsers

Source: CCN
Type: BugTraq Mailing List, Mon Jul 29 2002 - 17:38:27 CDT
RE: XWT Foundation Advisory

Source: CCN
Type: BugTraq Mailing List, Tue Jul 30 2002 - 12:16:17 CDT
RE: XWT Foundation Advisory: Firewall circumvention possible with all browsers

Source: CCN
Type: BugTraq Mailing List, Tue Jul 30 2002 - 04:50:40 CDT
RE: XWT Foundation Advisory

Source: CCN
Type: BugTraq Mailing List, Tue Jul 30 2002 - 14:32:13 CDT
RE: XWT Foundation Advisory

Source: CCN
Type: BugTraq Mailing List, Tue Jul 30 2002 - 01:11:34 CDT
RE: XWT Foundation Advisory: Firewall circumvention possible with all browsers

Source: CCN
Type: Bugzilla Bug 154930
document.domain abused to access hosts behind firewall

Source: MITRE
Type: CNA
CVE-2002-0815

Source: BUGTRAQ
Type: UNKNOWN
20020729 XWT Foundation Advisory: Firewall circumvention possible with all browsers

Source: BUGTRAQ
Type: UNKNOWN
20020729 RE: XWT Foundation Advisory

Source: CCN
Type: Microsoft Corporation Web site
Microsoft Windows Update

Source: CCN
Type: Mozilla Web site
mozilla.org

Source: CCN
Type: OSVDB ID: 14201
Multiple Browser Javascript "Same Origin Policy" Firewall Bypass

Source: CCN
Type: BID-5346
Multiple Browser Vendor Same Origin Policy Design Error Vulnerability

Source: XF
Type: UNKNOWN
javascript-sop-firewall-bypass(9726)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:mozilla:mozilla:*:*:*:*:*:*:*:*
  • OR cpe:/a:netscape:navigator:*:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:6.0.2900:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:netscape:navigator:*:*:*:*:*:*:*:*
  • OR cpe:/a:netscape:communicator:*:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:5.0:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:5.01:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:5.5:-:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:mozilla:0.9.6:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:mozilla:0.8:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:mozilla:0.9.9:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:mozilla:1.0:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:mozilla:0.9.2:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:mozilla:0.9.2.1:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:mozilla:0.9.3:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:mozilla:0.9.4:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:mozilla:0.9.5:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:mozilla:0.9.7:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:mozilla:0.9.8:*:*:*:*:*:*:*
  • AND
  • cpe:/o:mandrakesoft:mandrake_linux:8.2:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    mozilla mozilla *
    netscape navigator *
    microsoft internet explorer 6.0.2900
    netscape navigator *
    netscape communicator *
    microsoft ie 5.0
    microsoft ie 5.01
    microsoft ie 5.5
    microsoft ie 6.0
    mozilla mozilla 0.9.6
    mozilla mozilla 0.8
    mozilla mozilla 0.9.9
    mozilla mozilla 1.0
    mozilla mozilla 0.9.2
    mozilla mozilla 0.9.2.1
    mozilla mozilla 0.9.3
    mozilla mozilla 0.9.4
    mozilla mozilla 0.9.5
    mozilla mozilla 0.9.7
    mozilla mozilla 0.9.8
    mandrakesoft mandrake linux 8.2