CVE Vulnerabilities

CVE-2005-0588

Published: May 02, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Firefox before 1.0.1 and Mozilla before 1.7.6 does not restrict xsl:include and xsl:import tags in XSLT stylesheets to the current domain, which allows remote attackers to determine the existence of files on the local system.

Affected Software

NameVendorStart VersionEnd Version
FirefoxMozilla0.8 (including)0.8 (including)
FirefoxMozilla0.9 (including)0.9 (including)
FirefoxMozilla0.9-rc (including)0.9-rc (including)
FirefoxMozilla0.9.1 (including)0.9.1 (including)
FirefoxMozilla0.9.2 (including)0.9.2 (including)
FirefoxMozilla0.9.3 (including)0.9.3 (including)
FirefoxMozilla0.10 (including)0.10 (including)
FirefoxMozilla0.10.1 (including)0.10.1 (including)
FirefoxMozilla1.0 (including)1.0 (including)
MozillaMozilla1.3 (including)1.3 (including)
MozillaMozilla1.4 (including)1.4 (including)
MozillaMozilla1.4-alpha (including)1.4-alpha (including)
MozillaMozilla1.4.1 (including)1.4.1 (including)
MozillaMozilla1.5 (including)1.5 (including)
MozillaMozilla1.5-alpha (including)1.5-alpha (including)
MozillaMozilla1.5-rc1 (including)1.5-rc1 (including)
MozillaMozilla1.5-rc2 (including)1.5-rc2 (including)
MozillaMozilla1.5.1 (including)1.5.1 (including)
MozillaMozilla1.6 (including)1.6 (including)
MozillaMozilla1.6-alpha (including)1.6-alpha (including)
MozillaMozilla1.6-beta (including)1.6-beta (including)
MozillaMozilla1.7 (including)1.7 (including)
MozillaMozilla1.7-alpha (including)1.7-alpha (including)
MozillaMozilla1.7-beta (including)1.7-beta (including)
MozillaMozilla1.7-rc1 (including)1.7-rc1 (including)
MozillaMozilla1.7-rc2 (including)1.7-rc2 (including)
MozillaMozilla1.7-rc3 (including)1.7-rc3 (including)
MozillaMozilla1.7.1 (including)1.7.1 (including)
MozillaMozilla1.7.2 (including)1.7.2 (including)
MozillaMozilla1.7.3 (including)1.7.3 (including)
MozillaMozilla1.7.5 (including)1.7.5 (including)
Red Hat Enterprise Linux 4RedHatfirefox-0:1.0.1-1.4.3*
MozillaUbuntudapper*
MozillaUbuntuedgy*

References