Multiple Browser Weak Authentication Mechanism Vulnerability
BID:14325
Info
Multiple Browser Weak Authentication Mechanism Vulnerability
| Bugtraq ID: | 14325 |
| Class: | Design Error |
| CVE: |
CVE-2005-2395 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 19 2005 12:00AM |
| Updated: | Jul 12 2009 04:06PM |
| Credit: | Discovery is credited to ZARAZA <[email protected]>. |
| Vulnerable: |
Netscape Netscape 8.0.3 .3 Netscape Browser 8.0.3 .3 Mozilla Firefox 1.0.5 Mozilla Firefox 1.0.4 Mozilla Browser 1.7.11 Microsoft Internet Explorer 6.0 |
| Not Vulnerable: | |
Discussion
Multiple Browser Weak Authentication Mechanism Vulnerability
Multiple browser are affected by a vulnerability that may result in sending authentication credentials across the network in plaintext format.
By default, the browser chooses basic authentication even if other authentication schemas such as Digest or NTLM are available from the server.
Multiple browser are affected by a vulnerability that may result in sending authentication credentials across the network in plaintext format.
By default, the browser chooses basic authentication even if other authentication schemas such as Digest or NTLM are available from the server.
Exploit / POC
Multiple Browser Weak Authentication Mechanism Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Multiple Browser Weak Authentication Mechanism Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Multiple Browser Weak Authentication Mechanism Vulnerability
References:
References: