{"api_version":"1","generated_at":"2026-07-23T03:39:31+00:00","cve":"CVE-2008-0367","urls":{"html":"https://cve.report/CVE-2008-0367","api":"https://cve.report/api/cve/CVE-2008-0367.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-0367","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-0367"},"summary":{"title":"CVE-2008-0367","description":"Mozilla Firefox 2.0.0.11, 3.0b2, and possibly earlier versions, when prompting for HTTP Basic Authentication, displays the site requesting the authentication after the Realm text, which might make it easier for remote HTTP servers to conduct phishing and spoofing attacks.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-01-19 00:00:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-200","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/27111","name":"http://www.securityfocus.com/bid/27111","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Mozilla Firefox 'Basic Realm' Basic Authentication Header Spoofing Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://aviv.raffon.net/2008/01/02/YetAnotherDialogSpoofingFirefoxBasicAuthentication.aspx","name":"http://aviv.raffon.net/2008/01/02/YetAnotherDialogSpoofingFirefoxBasicAuthentication.aspx","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Aviv Raff On .NET - Yet another Dialog Spoofing - Firefox Basic Authentication","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://aviv.raffon.net/2008/01/05/FirefoxDialogSpoofingFAQ.aspx","name":"http://aviv.raffon.net/2008/01/05/FirefoxDialogSpoofingFAQ.aspx","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Aviv Raff On .NET - Firefox Dialog Spoofing - FAQ","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/485738/100/200/threaded","name":"http://www.securityfocus.com/archive/1/485738/100/200/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://blog.mozilla.com/security/2008/01/04/basicauth-dialog-realm-value-spoofing/","name":"http://blog.mozilla.com/security/2008/01/04/basicauth-dialog-realm-value-spoofing/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"BasicAuth dialog realm value spoofing  at  Mozilla Security Blog","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=244273","name":"https://bugzilla.mozilla.org/show_bug.cgi?id=244273","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"],"title":"244273 – (CVE-2008-0367) improve current HTTP authentication prompt","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/485732/100/200/threaded","name":"http://www.securityfocus.com/archive/1/485732/100/200/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-0367","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-0367","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"367","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"firefox","cpe6":"3.0","cpe7":"beta2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"367","vulnerable":"1","versionEndIncluding":"2.0.0.11","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"firefox","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T07:39:35.283Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://blog.mozilla.com/security/2008/01/04/basicauth-dialog-realm-value-spoofing/"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=244273"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://aviv.raffon.net/2008/01/05/FirefoxDialogSpoofingFAQ.aspx"},{"name":"20080103 Re: [Full-disclosure] Yet another Dialog Spoofing Vulnerability - Firefox Basic Authentication","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/485738/100/200/threaded"},{"name":"20080103 Yet another Dialog Spoofing Vulnerability - Firefox Basic Authentication","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/485732/100/200/threaded"},{"name":"27111","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/27111"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://aviv.raffon.net/2008/01/02/YetAnotherDialogSpoofingFirefoxBasicAuthentication.aspx"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-01-03T00:00:00.000Z","descriptions":[{"lang":"en","value":"Mozilla Firefox 2.0.0.11, 3.0b2, and possibly earlier versions, when prompting for HTTP Basic Authentication, displays the site requesting the authentication after the Realm text, which might make it easier for remote HTTP servers to conduct phishing and spoofing attacks."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-15T20:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://blog.mozilla.com/security/2008/01/04/basicauth-dialog-realm-value-spoofing/"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=244273"},{"tags":["x_refsource_MISC"],"url":"http://aviv.raffon.net/2008/01/05/FirefoxDialogSpoofingFAQ.aspx"},{"name":"20080103 Re: [Full-disclosure] Yet another Dialog Spoofing Vulnerability - Firefox Basic Authentication","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/485738/100/200/threaded"},{"name":"20080103 Yet another Dialog Spoofing Vulnerability - Firefox Basic Authentication","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/485732/100/200/threaded"},{"name":"27111","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/27111"},{"tags":["x_refsource_MISC"],"url":"http://aviv.raffon.net/2008/01/02/YetAnotherDialogSpoofingFirefoxBasicAuthentication.aspx"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-0367","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Mozilla Firefox 2.0.0.11, 3.0b2, and possibly earlier versions, when prompting for HTTP Basic Authentication, displays the site requesting the authentication after the Realm text, which might make it easier for remote HTTP servers to conduct phishing and spoofing attacks."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://blog.mozilla.com/security/2008/01/04/basicauth-dialog-realm-value-spoofing/","refsource":"CONFIRM","url":"http://blog.mozilla.com/security/2008/01/04/basicauth-dialog-realm-value-spoofing/"},{"name":"https://bugzilla.mozilla.org/show_bug.cgi?id=244273","refsource":"CONFIRM","url":"https://bugzilla.mozilla.org/show_bug.cgi?id=244273"},{"name":"http://aviv.raffon.net/2008/01/05/FirefoxDialogSpoofingFAQ.aspx","refsource":"MISC","url":"http://aviv.raffon.net/2008/01/05/FirefoxDialogSpoofingFAQ.aspx"},{"name":"20080103 Re: [Full-disclosure] Yet another Dialog Spoofing Vulnerability - Firefox Basic Authentication","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/485738/100/200/threaded"},{"name":"20080103 Yet another Dialog Spoofing Vulnerability - Firefox Basic Authentication","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/485732/100/200/threaded"},{"name":"27111","refsource":"BID","url":"http://www.securityfocus.com/bid/27111"},{"name":"http://aviv.raffon.net/2008/01/02/YetAnotherDialogSpoofingFirefoxBasicAuthentication.aspx","refsource":"MISC","url":"http://aviv.raffon.net/2008/01/02/YetAnotherDialogSpoofingFirefoxBasicAuthentication.aspx"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-0367","datePublished":"2008-01-18T23:00:00.000Z","dateReserved":"2008-01-18T00:00:00.000Z","dateUpdated":"2024-08-07T07:39:35.283Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-01-19 00:00:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-200","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*","versionEndIncluding":"2.0.0.11","matchCriteriaId":"B3E4F934-1CC7-475C-B425-BEEF29AED912"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:3.0:beta2:*:*:*:*:*:*","matchCriteriaId":"13AAF607-AEEE-4FAF-BE63-73B1D951EF52"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"367","Ordinal":"1","Title":"CVE-2008-0367","CVE":"CVE-2008-0367","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"367","Ordinal":"1","NoteData":"Mozilla Firefox 2.0.0.11, 3.0b2, and possibly earlier versions, when prompting for HTTP Basic Authentication, displays the site requesting the authentication after the Realm text, which might make it easier for remote HTTP servers to conduct phishing and spoofing attacks.","Type":"Description","Title":"CVE-2008-0367"},{"CveYear":"2008","CveId":"367","Ordinal":"2","NoteData":"2008-01-18","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"367","Ordinal":"3","NoteData":"2018-10-15","Type":"Other","Title":"Modified"}]}}}