Mozilla before 1.6 does not display the entire URL in the status bar when a link contains %00, which could allow remote attackers to trick users into clicking on unknown or untrusted sites and facilitate phishing attacks.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2004-12-31 05:00
Updated : 2008-09-05 20:41
NVD link : CVE-2004-1451
Mitre link : CVE-2004-1451
CVE.ORG link : CVE-2004-1451
JSON object : View
Products Affected
mozilla
- mozilla
CWE