« Volver al listado

CVE-2002-1151

Estado: ModificadaAlta (7.5)—

The cross-site scripting protection for Konqueror in KDE 2.2.2 and 3.0 through 3.0.3 does not properly initialize the domains on sub-frames and sub-iframes, which can allow remote attackers to execute script and steal cookies from subframes that are in other domains.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2002-1151",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": true,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2002-10-11T04:00:00.000",
  "references": [
    {
      "url": "ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-047.0.txt",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000525",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://marc.info/?l=bugtraq&m=103175850925395&w=2",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.debian.org/security/2002/dsa-167",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.iss.net/security_center/static/10039.php",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.kde.org/info/security/advisory-20020908-2.txt",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-064.php",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.osvdb.org/7867",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.redhat.com/support/errata/RHSA-2002-220.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.redhat.com/support/errata/RHSA-2002-221.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/5689",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-047.0.txt",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000525",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://marc.info/?l=bugtraq&m=103175850925395&w=2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.debian.org/security/2002/dsa-167",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.iss.net/security_center/static/10039.php",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.kde.org/info/security/advisory-20020908-2.txt",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-064.php",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.osvdb.org/7867",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.redhat.com/support/errata/RHSA-2002-220.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.redhat.com/support/errata/RHSA-2002-221.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/5689",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The cross-site scripting protection for Konqueror in KDE 2.2.2 and 3.0 through 3.0.3 does not properly initialize the domains on sub-frames and sub-iframes, which can allow remote attackers to execute script and steal cookies from subframes that are in other domains."
    },
    {
      "lang": "es",
      "value": "La protección de ejecución de secuencias de comandos (scripts) en sitios cruzados en Konqueror 2.2.2 y 3.0 a 3.0.3 no inicializa adecuandamente los dominios en sub-marcos y sub-iframes (marcos incrustados), lo que puede permitir que atacantes remotos ejecuten comandos y roben cookies de submarcos que están en otros dominios."
    }
  ],
  "lastModified": "2026-06-16T21:58:49.167",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:kde:konqueror:2.2.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D435E39F-4F70-481B-9225-B072B79BEB69"
            },
            {
              "criteria": "cpe:2.3:a:kde:konqueror:3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8AD68BAB-8945-4A22-938E-12C01D0111D0"
            },
            {
              "criteria": "cpe:2.3:a:kde:konqueror:3.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7B3220BF-B0AF-4C90-89BD-B425EE58021D"
            },
            {
              "criteria": "cpe:2.3:a:kde:konqueror:3.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FA53FB7A-AF7F-45B2-AF23-11B1FC4EC289"
            },
            {
              "criteria": "cpe:2.3:a:kde:konqueror:3.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "619EB7F6-8694-4344-A4C9-A35DA58391AB"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:kde:kde:2.2.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3F531972-E0A7-4E7C-A899-3766CEAAE2EF"
            },
            {
              "criteria": "cpe:2.3:o:kde:kde:3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4CEED379-3111-4451-B782-8C66CE568A1C"
            },
            {
              "criteria": "cpe:2.3:o:kde:kde:3.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B146FCD3-F6E7-4412-94FD-F9E66089C227"
            },
            {
              "criteria": "cpe:2.3:o:kde:kde:3.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "99CB51E4-0BFC-4C7C-B9EE-3DBCB0188D73"
            },
            {
              "criteria": "cpe:2.3:o:kde:kde:3.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C629F0C8-C765-4076-B426-80929F9CE285"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}