Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g63h-wr5c-mmgm

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Firefox before 1.0.1 and Mozilla before 1.7.6 does not restrict xsl:include and xsl:import tags in XSLT stylesheets to the current domain, which allows remote attackers to determine the existence of files on the local system.

Firefox before 1.0.1 and Mozilla before 1.7.6 does not restrict xsl:include and xsl:import tags in XSLT stylesheets to the current domain, which allows remote attackers to determine the existence of files on the local system.

EPSS

Процентиль: 80%
0.01477
Низкий

Связанные уязвимости

ubuntu
около 20 лет назад

Firefox before 1.0.1 and Mozilla before 1.7.6 does not restrict xsl:include and xsl:import tags in XSLT stylesheets to the current domain, which allows remote attackers to determine the existence of files on the local system.

redhat
больше 20 лет назад

Firefox before 1.0.1 and Mozilla before 1.7.6 does not restrict xsl:include and xsl:import tags in XSLT stylesheets to the current domain, which allows remote attackers to determine the existence of files on the local system.

nvd
около 20 лет назад

Firefox before 1.0.1 and Mozilla before 1.7.6 does not restrict xsl:include and xsl:import tags in XSLT stylesheets to the current domain, which allows remote attackers to determine the existence of files on the local system.

debian
около 20 лет назад

Firefox before 1.0.1 and Mozilla before 1.7.6 does not restrict xsl:in ...

EPSS

Процентиль: 80%
0.01477
Низкий