Open Vulnerability and Assessment Language (OVAL)
Contact Us Downloads News July 2, 2009 Search
link to OVAL home page

View Definition

Definition Id: oval:org.mitre.oval:def:100041 Date: 2007-04-23
Title: Mozilla 'user:pass@host' Spoofing Vulnerability
Description: The installation confirmation dialog in Firefox before 1.0.1, Thunderbird before 1.0.1, and Mozilla before 1.7.6 allows remote attackers to use InstallTrigger to spoof the hostname of the host performing the installation via a long "user:pass" sequence in the URL, which appears before the real hostname.
Version: 5 Class: vulnerability
Status: ACCEPTED Reference(s): CVE-2005-0590
Family: windows
Platform(s): Microsoft Windows NT
Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Server 2003
Product(s): mozilla
Mozilla Firefox
Mozilla Thunderbird
Definition Synopsis:

OVAL is CVE Compatible