Vulnerability Name:

CVE-2002-2314 (CCN-9656)

Assigned:2002-07-24
Published:2002-07-24
Updated:2008-09-05
Summary:Mozilla 1.0 allows remote attackers to steal cookies from other domains via a javascript: URL with a leading "//" and ending in a newline, which causes the host/path check to fail.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-20
Vulnerability Consequences:Obtain Information
References:Source: CCN
Type: BugTraq Mailing List, Wed Jul 24 2002 - 09:45:59 CDT
Mozilla cookie stealing - Sandblad advisory #9

Source: MISC
Type: Exploit
http://bugzilla.mozilla.org/show_bug.cgi?id=152725

Source: BUGTRAQ
Type: UNKNOWN
20020918 Mozilla vulnerabilities, an update

Source: MITRE
Type: CNA
CVE-2002-2314

Source: BUGTRAQ
Type: Exploit
20020724 Mozilla cookie stealing - Sandblad advisory #9

Source: XF
Type: Exploit, Patch
mozilla-javascript-steal-cookies(9656)

Source: MANDRAKE
Type: UNKNOWN
MDKSA-2002:074

Source: CCN
Type: Mozilla Web site
mozilla.org

Source: CONFIRM
Type: UNKNOWN
http://www.mozilla.org/releases/mozilla1.0.1/security-fixes-1.0.1.html

Source: CCN
Type: OSVDB ID: 60255
Mozilla Crafted Javascript URI Cross-domain Cookie Disclosure

Source: BID
Type: UNKNOWN
5293

Source: CCN
Type: BID-5293
Mozilla JavaScript URL Host Spoofing Arbitrary Cookie Access Vulnerability

Source: XF
Type: UNKNOWN
mozilla-javascript-steal-cookies(9656)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:mozilla:mozilla:1.0:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:mozilla:mozilla:0.9.6:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:mozilla:0.8:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:mozilla:0.9.9:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:mozilla:1.0:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:mozilla:0.9.2:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:mozilla:0.9.2.1:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:mozilla:0.9.3:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:mozilla:0.9.4:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:mozilla:0.9.4.1:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:mozilla:0.9.5:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:mozilla:0.9.7:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:mozilla:0.9.8:*:*:*:*:*:*:*
  • AND
  • cpe:/o:apple:macos:9.0:*:*:*:*:*:*:*
  • OR cpe:/o:apple:macos:8.0:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:8.2:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    mozilla mozilla 1.0
    mozilla mozilla 0.9.6
    mozilla mozilla 0.8
    mozilla mozilla 0.9.9
    mozilla mozilla 1.0
    mozilla mozilla 0.9.2
    mozilla mozilla 0.9.2.1
    mozilla mozilla 0.9.3
    mozilla mozilla 0.9.4
    mozilla mozilla 0.9.4.1
    mozilla mozilla 0.9.5
    mozilla mozilla 0.9.7
    mozilla mozilla 0.9.8
    apple mac os 9.0
    apple mac os 8.0
    mandrakesoft mandrake linux 8.2