CVE-2005-1576
N/A
N/A
Summary
The file download dialog in Mozilla Firefox 0.10.1 and 1.0 for Windows uses the Content-Type HTTP header to determine the file type, but saves the original file extension when "Save to Disk" is selected, which allows remote attackers to hide the real file types of downloaded files.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www.osvdb.org/16432
- http://secunia.com/secunia_research/2004-11/advisory/
- http://secunia.com/advisories/12979
References
- http://www.osvdb.org/16432
- http://secunia.com/secunia_research/2004-11/advisory/
- http://secunia.com/advisories/12979
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.