Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2005-0588

Опубликовано: 02 мая 2005
Источник: ubuntu
Приоритет: untriaged
EPSS Низкий
CVSS2: 5

Описание

Firefox before 1.0.1 and Mozilla before 1.7.6 does not restrict xsl:include and xsl:import tags in XSLT stylesheets to the current domain, which allows remote attackers to determine the existence of files on the local system.

РелизСтатусПримечание
dapper

released

1.7.12-1.1ubuntu2
devel

DNE

edgy

released

1.7.12-1.1ubuntu2
feisty

DNE

upstream

needs-triage

Показывать по

EPSS

Процентиль: 80%
0.01477
Низкий

5 Medium

CVSS2

Связанные уязвимости

redhat
больше 20 лет назад

Firefox before 1.0.1 and Mozilla before 1.7.6 does not restrict xsl:include and xsl:import tags in XSLT stylesheets to the current domain, which allows remote attackers to determine the existence of files on the local system.

nvd
около 20 лет назад

Firefox before 1.0.1 and Mozilla before 1.7.6 does not restrict xsl:include and xsl:import tags in XSLT stylesheets to the current domain, which allows remote attackers to determine the existence of files on the local system.

debian
около 20 лет назад

Firefox before 1.0.1 and Mozilla before 1.7.6 does not restrict xsl:in ...

github
около 3 лет назад

Firefox before 1.0.1 and Mozilla before 1.7.6 does not restrict xsl:include and xsl:import tags in XSLT stylesheets to the current domain, which allows remote attackers to determine the existence of files on the local system.

EPSS

Процентиль: 80%
0.01477
Низкий

5 Medium

CVSS2