Unrated severityNVD Advisory· Published Feb 5, 2014· Updated Apr 29, 2026
CVE-2013-2074
CVE-2013-2074
Description
kioslave/http/http.cpp in KIO in kdelibs 4.10.3 and earlier allows attackers to discover credentials via a crafted request that triggers an "internal server error," which includes the username and password in an error message.
Affected products
4Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- bugs.kde.org/show_bug.cginvdVendor Advisory
- bugs.debian.org/cgi-bin/bugreport.cginvd
- ubuntu.com/usn/usn-1842-1nvd
- www.openwall.com/lists/oss-security/2013/05/10/4nvd
- www.openwall.com/lists/oss-security/2013/05/11/2nvd
- www.osvdb.org/93244nvd
- xorl.wordpress.com/2013/05/22/cve-2013-2074-kde-kdelibs-password-exposure/nvd
- bugzilla.redhat.com/show_bug.cginvd
- projects.kde.org/projects/kde/kdelibs/repository/revisions/65d736dab592bced4410ccfa4699de89f78c96ca/diff/kioslave/http/http.cppnvd
News mentions
0No linked articles in our index yet.