CVE-2008-0367
CVSS V2 Medium 5
CVSS V3 None
Description
Mozilla Firefox 2.0.0.11, 3.0b2, and possibly earlier versions, when prompting for HTTP Basic Authentication, displays the site requesting the authentication after the Realm text, which might make it easier for remote HTTP servers to conduct phishing and spoofing attacks.
Overview
- CVE ID
- CVE-2008-0367
- Assigner
- cve@mitre.org
- Vulnerability Status
- Analyzed
- Published Version
- 2008-01-19T00:00:00
- Last Modified Date
- 2018-10-26T14:19:22
Weakness Enumerations
CPE Configuration (Product)
CPE | Vulnerable | Operator | Version Start | Version End |
---|---|---|---|---|
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | 1 | OR | 2.0.0.11 | |
cpe:2.3:a:mozilla:firefox:3.0:beta2:*:*:*:*:*:* | 1 | OR |
CVSS Version 2
- Version
- 2.0
- Vector String
- AV:N/AC:L/Au:N/C:N/I:P/A:N
- Access Vector
- NETWORK
- Access Compatibility
- LOW
- Authentication
- NONE
- Confidentiality Impact
- NONE
- Integrity Impact
- PARTIAL
- Availability Impact
- NONE
- Base Score
- 5
- Severity
- MEDIUM
- Exploitability Score
- 10
- Impact Score
- 2.9
References
Reference URL | Reference Tags |
---|---|
http://aviv.raffon.net/2008/01/02/YetAnotherDialogSpoofingFirefoxBasicAuthentication.aspx | Third Party Advisory |
http://aviv.raffon.net/2008/01/05/FirefoxDialogSpoofingFAQ.aspx | Third Party Advisory |
http://blog.mozilla.com/security/2008/01/04/basicauth-dialog-realm-value-spoofing/ | Vendor Advisory |
https://bugzilla.mozilla.org/show_bug.cgi?id=244273 | Issue Tracking Vendor Advisory |
http://www.securityfocus.com/bid/27111 | Third Party Advisory VDB Entry |
http://www.securityfocus.com/archive/1/485738/100/200/threaded | Third Party Advisory VDB Entry |
http://www.securityfocus.com/archive/1/485732/100/200/threaded | Third Party Advisory VDB Entry |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2008-0367 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0367 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2022-05-10 18:02:41 | Added to TrackCVE |