Vulnerabilities > CVE-2001-0596 - Information Disclosure vulnerability in Netscape Navigator 'about:' Domain

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
netscape
nessus
exploit available

Summary

Netscape Communicator before 4.77 allows remote attackers to execute arbitrary Javascript via a GIF image whose comment contains the Javascript.

Exploit-Db

descriptionNetscape Navigator 4.0.8 'about:' Domain Information Disclosure Vulnerability. CVE-2001-0596. Remote exploit for unix platform
idEDB-ID:20791
last seen2016-02-02
modified2001-04-09
published2001-04-09
reporterFlorian Wesch
sourcehttps://www.exploit-db.com/download/20791/
titleNetscape Navigator 4.0.8 - 'about:' Domain Information Disclosure Vulnerability

Nessus

NASL familyDebian Local Security Checks
NASL idDEBIAN_DSA-051.NASL
descriptionFlorian Wesch has discovered a problem (reported to bugtraq) with the way how Netscape handles comments in GIF files. The Netscape browser does not escape the GIF file comment in the image information page. This allows JavaScript execution in the
last seen2020-06-01
modified2020-06-02
plugin id14888
published2004-09-29
reporterThis script is Copyright (C) 2004-2019 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/14888
titleDebian DSA-051-1 : netscape - unexpected javascript execution

Redhat

advisories
rhsa
idRHSA-2001:046