Mozilla before 1.6 does not display the entire URL in the status bar when a link contains %00, which could allow remote attackers to trick users into clicking on unknown or untrusted sites and facilitate phishing attacks.
References
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:50
Type | Values Removed | Values Added |
---|---|---|
References | () http://bugzilla.mozilla.org/show_bug.cgi?id=228176 - Exploit, Patch | |
References | () http://secunia.com/advisories/10419/ - Exploit | |
References | () http://www.mozilla.org/projects/security/known-vulnerabilities.html - |
Information
Published : 2004-12-31 05:00
Updated : 2024-11-20 23:50
NVD link : CVE-2004-1451
Mitre link : CVE-2004-1451
CVE.ORG link : CVE-2004-1451
JSON object : View
Products Affected
mozilla
- mozilla
CWE