CVE-2002-2013
Mozilla 0.9.6 and earlier and Netscape 6.2 and earlier allows remote attackers to steal cookies from another domain via a link with a hex-encoded null character (%00) followed by the target domain.
- Affected products
- Mozilla Firefox, Netscape
- Mozilla
- = 0.9.2, 0.9.2.1, 0.9.3, 0.9.4, 0.9.4.1, 0.9.5, 0.9.6
- Netscape Communicator
- = 4.0, 4.4, 4.5, 4.5_beta, 4.06, 4.6, 4.07, 4.7, 4.08, 4.51, 4.61, 4.72, 4.73, 4.74, 4.75, 4.76, 4.77, 4.78
- Netscape Navigator
- = 4.77, 6.0, 6.01, 6.1, 6.2
- Fix
- Available
- CVSS 2.0
- 5.0 MEDIUM
- EPSS
- 1.6% (74th percentile)
- NVD status
- Modified
- Published
- 2005-07-14
CVE-2002-2013 at NVD
No indexed exploits for CVE-2002-2013 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2002-2013 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.