CVE-2005-0588: Medium severity Mozilla Firefox vulnerability
Firefox before 1.0.1 and Mozilla before 1.7.6 does not restrict xsl:include and xsl:import tags in XSLT stylesheets to the current domain, which allows remote attackers to determine the existence of files on the local system.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-0588?
CVE-2005-0588 is considered a moderate severity vulnerability as it allows attackers to determine the existence of files on the local system.
How do I fix CVE-2005-0588?
To fix CVE-2005-0588, users should upgrade to Firefox version 1.0.1 or later and Mozilla 1.7.6 or later.
Which versions are affected by CVE-2005-0588?
CVE-2005-0588 affects Mozilla products before version 1.7.6 and Firefox versions earlier than 1.0.1.
What type of attack does CVE-2005-0588 enable?
CVE-2005-0588 enables remote attackers to exploit XSLT stylesheets to probe for file existence on the victim's system.
Is there a workaround for CVE-2005-0588?
There are no known effective workarounds for CVE-2005-0588 other than updating to a secure version.