← Back

CVE-2003-0592

nvd nist
Published: Apr 15, 2004Modified: Apr 16, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

Konqueror in KDE 3.1.3 and earlier (kdelibs) allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Konqueror to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.

Affected (11)

2 products
Konqueror
Konqueror Embedded
Configuration A
11 vulnerable
Vulnerable SoftwareAffected Versions
Kde
Version 2.1.1
Version 2.2.2
Version 3.0.1
Version 3.0.2
Version 3.0.3
Version 3.0.5
Version 3.0
Version 3.1.1
Version 3.1.2
Version 3.1
Version 0.1

References (12)

Timeline

No history available yet.