CVE-2008-1238
27.03.2008, 10:44
Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9, when generating the HTTP Referer header, does not list the entire URL when it contains Basic Authentication credentials without a username, which makes it easier for remote attackers to bypass application protection mechanisms that rely on Referer headers, such as with some Cross-Site Request Forgery (CSRF) mechanisms.Enginsight
Vendor | Product | Version |
---|---|---|
mozilla | firefox | 𝑥 ≤ 2.0.0.12 |
mozilla | seamonkey | 𝑥 ≤ 1.1.8 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
firefox |
| ||||||||||||
iceape |
| ||||||||||||
iceweasel |
| ||||||||||||
seamonkey |
| ||||||||||||
xulrunner |
|
Common Weakness Enumeration
References