CVE-2008-1238
27.03.2008, 10:44
Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9, when generating the HTTP Referer header, does not list the entire URL when it contains Basic Authentication credentials without a username, which makes it easier for remote attackers to bypass application protection mechanisms that rely on Referer headers, such as with some Cross-Site Request Forgery (CSRF) mechanisms.Enginsight
| Vendor | Product | Version |
|---|---|---|
| mozilla | firefox | 𝑥 ≤ 2.0.0.12 |
| mozilla | seamonkey | 𝑥 ≤ 1.1.8 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Ubuntu Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| firefox |
| ||||||||||||
| iceape |
| ||||||||||||
| iceweasel |
| ||||||||||||
| seamonkey |
| ||||||||||||
| xulrunner |
|
Common Weakness Enumeration
References