Lucene search

K
nvd[email protected]NVD:CVE-2003-0514
HistoryApr 15, 2004 - 4:00 a.m.

CVE-2003-0514

2004-04-1504:00:00
web.nvd.nist.gov
7

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.1

Confidence

Low

EPSS

0.05

Percentile

93.0%

Apple Safari allows remote attackers to bypass intended cookie access restrictions on a web application via “%2e%2e” (encoded dot dot) directory traversal sequences in a URL, which causes Safari to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.

Affected configurations

Nvd
Node
applesafariMatch1.0
OR
applesafariMatch1.1
VendorProductVersionCPE
applesafari1.0cpe:2.3:a:apple:safari:1.0:*:*:*:*:*:*:*
applesafari1.1cpe:2.3:a:apple:safari:1.1:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.1

Confidence

Low

EPSS

0.05

Percentile

93.0%

Related for NVD:CVE-2003-0514