CVE-2004-1158 describes a "window injection" vulnerability in Konqueror 3.x, including versions up to 3.2.2-6, and potentially other versions, affecting various Linux distributions like Fedora Core and Mandrake Linux. This flaw allows remote attackers to spoof legitimate websites by injecting content from one window into another target window or tab, even if they originate from different domains, provided the target window's name is known. The vulnerability carries a CVSS score of 7.5, indicating high severity with a network-based attack vector, low attack complexity, and potential for partial impact on confidentiality, integrity, and availability. Its FAUCET Risk Score is 88/100. Despite its age, there is no evidence of active exploitation, nor are there known exploits available in Metasploit or ExploitDB. However, the CVE has garnered significant community discussion with 10 mentions, suggesting ongoing awareness or interest, though it lacks media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.1.1CPE matchmatch criteria | cpe:2.3:a:kde:konqueror:2.1.1:*:*:*:*:*:*:* | ||
2.1.2CPE matchmatch criteria | cpe:2.3:a:kde:konqueror:2.1.2:*:*:*:*:*:*:* | ||
2.2.1CPE matchmatch criteria | cpe:2.3:a:kde:konqueror:2.2.1:*:*:*:*:*:*:* | ||
2.2.2CPE matchmatch criteria | cpe:2.3:a:kde:konqueror:2.2.2:*:*:*:*:*:*:* | ||
3.0CPE matchmatch criteria | cpe:2.3:a:kde:konqueror:3.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.