Netscape JavaScript Cache Browsing Vulnerability
BID:6796
Info
Netscape JavaScript Cache Browsing Vulnerability
| Bugtraq ID: | 6796 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 29 1998 12:00AM |
| Updated: | Sep 29 1998 12:00AM |
| Credit: | This vulnerability was reported by [email protected]. |
| Vulnerable: |
Netscape Navigator 4.0 7 Netscape Navigator 4.0 6 Netscape Navigator 3.0 4 |
| Not Vulnerable: | |
Discussion
Netscape JavaScript Cache Browsing Vulnerability
A vulnerability has been reported for Netscape that may reveal the contents of users' cached information to remote attackers.
An attacker can exploit this vulnerability by enticing a user to visit a malicious Web site. The Web site contains JavaScript code that will exploit this vulnerability.
A vulnerability has been reported for Netscape that may reveal the contents of users' cached information to remote attackers.
An attacker can exploit this vulnerability by enticing a user to visit a malicious Web site. The Web site contains JavaScript code that will exploit this vulnerability.
Exploit / POC
Netscape JavaScript Cache Browsing Vulnerability
Two proof of concepts are available in the referenced message.
Two proof of concepts are available in the referenced message.
Solution / Fix
Netscape JavaScript Cache Browsing Vulnerability
Solution:
Newer versions of Netscape are not vulnerable to this issue. Users are advised to upgrade to Netscape 6 or later.
Solution:
Newer versions of Netscape are not vulnerable to this issue. Users are advised to upgrade to Netscape 6 or later.
References
Netscape JavaScript Cache Browsing Vulnerability
References:
References:
- Netscape Homepage (Netscape)
- The JavaScript Cache Browsing Bug (Netscape)