Secunia Logo
 
CVE Reference: CVE-2004-0870
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2004-0870

Description:
KDE Konqueror does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers to steal cookies and conduct unauthorized activities, aka "Cross Security Boundary Cookie Injection."

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/17417

ST
  1011330

MISC
  http://www.westpoint.ltd.uk/advisories/wp-04-0001.txt

BUGTRAQ
  http://securityfocus.com/archive/1/375407


Return to the previous page.