CVE-2003-0459

KDE Konqueror for KDE 3.1.2 and earlier does not remove authentication credentials from URLs of the "user:password@host" form in the HTTP-Referer header, which could allow remote web sites to steal the credentials for pages that link to the sites.

Scoring

CVSS base score
0.06
EPSS probability
1.52%
Published
2003-08-01
Last modified
2026-03-16

Affected products

Markdown version · Browse all CVEs