KDE Konqueror for KDE 3.1.2 and earlier does not remove authentication credentials from URLs of the "user:password@host" form in the HTTP-Referer header, which could allow remote web sites to steal the credentials for pages that link to the sites.
Get an AI-powered plain-language explanation of this vulnerability and remediation steps.
Login to generate AI explanation20 reference(s) from NVD