« Back to list

CVE-2002-0354

Status: ModifiedMedium (5)—

The XMLHttpRequest object (XMLHTTP) in Netscape 6.1 and Mozilla 0.9.7 allows remote attackers to read arbitrary files and list directories on a client system by opening a URL that redirects the browser to the file on the client, then reading the result using the responseText property.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (2)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2002-0354",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2002-06-25T04:00:00.000",
  "references": [
    {
      "url": "http://marc.info/?l=bugtraq&m=102017952204097&w=2",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://marc.info/?l=ntbugtraq&m=102020343728766&w=2",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://marc.info/?l=bugtraq&m=102017952204097&w=2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://marc.info/?l=ntbugtraq&m=102020343728766&w=2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The XMLHttpRequest object (XMLHTTP) in Netscape 6.1 and Mozilla 0.9.7 allows remote attackers to read arbitrary files and list directories on a client system by opening a URL that redirects the browser to the file on the client, then reading the result using the responseText property."
    }
  ],
  "lastModified": "2026-06-16T21:57:16.540",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:mozilla:mozilla:0.9.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1E4F64F8-CCC2-47FF-9B9D-41B3BCDD513C"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:mozilla:0.9.9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9F1EB38F-CEB2-40BC-AA5D-CC539F597137"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:mozilla:1.0:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C9296197-0EE0-4CC0-A11F-E44E3443E990"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:mozilla:1.0:rc2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A76ACC55-754D-4501-8312-5A4E10D053B8"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:mozilla:1.0:rc3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "347AB95F-166E-449A-82D7-BEC10257E0D1"
            },
            {
              "criteria": "cpe:2.3:a:netscape:navigator:6.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4F112CED-879B-4A19-993A-16858B4EC16C"
            },
            {
              "criteria": "cpe:2.3:a:netscape:navigator:6.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B7D7FA24-4B6F-4D67-95BE-46819033CA6F"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}