Symantec.com > Business > Security Response > Attack Signatures > HTTP Netscape Cookie Monster

HTTP Netscape Cookie Monster

Severity: Medium

This attack could pose a moderate security threat. It does not require immediate action.

Description

This signature detects an attempt to access the locally stored cookies on the victim system.

Additional Information

A vulnerability has been reported for Netscape that may reveal the contents of users' cached information to remote attackers.

An attacker can exploit this vulnerability by enticing a user to visit a malicious Web site. The Web site contains JavaScript code that will exploit this vulnerability.

Affected

  • Netscape Navigator 3.0 4, 4.0 6, 4.0 7

Response

Newer versions of Netscape are not vulnerable to this issue. Users are advised to upgrade to Netscape 6 or later.