CVE
- Id
- 11794
- CVE No.
- CVE-2005-0588
- Status
- Candidate
- Description
- Firefox before 1.0.1 and Mozilla before 1.7.6 does not restrict xsl:include and xsl:import tags in XSLT stylesheets to the current domain, which allows remote attackers to determine the existence of files on the local system.
- Phase
- Assigned (20050228)
- Votes
- None (candidate not yet proposed)
- Comments