CVE-2002-1151 PUBLISHED CVSS 7.5 HIGH

The cross-site scripting protection for Konqueror in KDE 2.2.2 and 3.0 through 3.0.3 does not properly initialize the domains on sub-frames and sub-iframes, which can allow remote attackers to execute script and steal cookies from subframes that are in other domains.

EPSS 3.22% · 87.0th percentile

Risk Scores

CVSS v2.0
7.5
EPSS Score
3.22%
87.0th percentile

Affected Products

VendorProductVersions
n/an/an/a
kdekde3.0.3, 2.2.2, 3.0
kdekonqueror2.2.2, 3.0, 3.0.1

Timeline

References

Open in Interactive Console →