CVE-2008-0367
Summary
| CVE | CVE-2008-0367 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-01-19 00:00:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Mozilla Firefox 2.0.0.11, 3.0b2, and possibly earlier versions, when prompting for HTTP Basic Authentication, displays the site requesting the authentication after the Realm text, which might make it easier for remote HTTP servers to conduct phishing and spoofing attacks. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Mozilla Firefox 'Basic Realm' Basic Authentication Header Spoofing Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Aviv Raff On .NET - Yet another Dialog Spoofing - Firefox Basic Authentication | af854a3a-2127-422b-91ae-364da2661108 | aviv.raffon.net | Third Party Advisory |
| Aviv Raff On .NET - Firefox Dialog Spoofing - FAQ | af854a3a-2127-422b-91ae-364da2661108 | aviv.raffon.net | Third Party Advisory |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| BasicAuth dialog realm value spoofing at Mozilla Security Blog | af854a3a-2127-422b-91ae-364da2661108 | blog.mozilla.com | Vendor Advisory |
| 244273 – (CVE-2008-0367) improve current HTTP authentication prompt | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | Issue Tracking, Vendor Advisory |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.