Mozilla before 1.6 does not display the entire URL in the status bar when a link contains %00, which could allow remote attackers to trick users into clicking on unknown or untrusted sites and facilitate phishing attacks.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2004-12-30 21:00
Updated : 2008-09-05 13:41
NVD link : CVE-2004-1451
Mitre link : CVE-2004-1451
JSON object : View
CWE
Products Affected
mozilla
- mozilla