Vulnerability Description
Mozilla before 1.6 does not display the entire URL in the status bar when a link contains %00, which could allow remote attackers to trick users into clicking on unknown or untrusted sites and facilitate phishing attacks.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Mozilla | 0.8 |
References
- http://bugzilla.mozilla.org/show_bug.cgi?id=228176ExploitPatch
- http://secunia.com/advisories/10419/Exploit
- http://www.mozilla.org/projects/security/known-vulnerabilities.html
- http://bugzilla.mozilla.org/show_bug.cgi?id=228176ExploitPatch
- http://secunia.com/advisories/10419/Exploit
- http://www.mozilla.org/projects/security/known-vulnerabilities.html
FAQ
What is CVE-2004-1451?
CVE-2004-1451 is a vulnerability with a CVSS score of 2.6 (LOW). Mozilla before 1.6 does not display the entire URL in the status bar when a link contains %00, which could allow remote attackers to trick users into clicking on unknown or untrusted sites and facilit...
How severe is CVE-2004-1451?
CVE-2004-1451 has been rated LOW with a CVSS base score of 2.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-1451?
Check the references section above for vendor advisories and patch information. Affected products include: Mozilla Mozilla.