The installation confirmation dialog in Firefox before 1.0.1, Thunderbird before 1.0.1, and Mozilla before 1.7.6 allows remote attackers to use InstallTrigger to spoof the hostname of the host performing the installation via a long "user:pass" sequence in the URL, which appears before the real hostname.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2005-02-28T05:00:00

Updated: 2024-08-07T21:21:06.511Z

Reserved: 2005-02-28T00:00:00

Link: CVE-2005-0590

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2005-05-02T04:00:00.000

Modified: 2017-10-11T01:29:58.483

Link: CVE-2005-0590

cve-icon Redhat

Severity : Low

Publid Date: 2005-02-24T00:00:00Z

Links: CVE-2005-0590 - Bugzilla