Security Advisory

CVE-2005-0590

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2005-02-28 05:00:00
Last updated 2024-08-07 21:21:06
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

The installation confirmation dialog in Firefox before 1.0.1, Thunderbird before 1.0.1, and Mozilla before 1.7.6 allows remote attackers to use InstallTrigger to spoof the hostname of the host performing the installation via a long "user:pass" sequence in the URL, which appears before the real hostname.