Mozilla Firefox 'Basic Realm' Basic Authentication Header Spoofing Vulnerability
BID:27111
Info
Mozilla Firefox 'Basic Realm' Basic Authentication Header Spoofing Vulnerability
| Bugtraq ID: | 27111 |
| Class: | Design Error |
| CVE: |
CVE-2008-0367 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 02 2008 12:00AM |
| Updated: | Apr 16 2015 06:07PM |
| Credit: | Aviv Raff discovered this issue. |
| Vulnerable: |
Mozilla Firefox 2.0 .9 Mozilla Firefox 2.0 .8 Mozilla Firefox 2.0 .7 Mozilla Firefox 2.0 .6 Mozilla Firefox 2.0 .5 Mozilla Firefox 2.0 .4 Mozilla Firefox 2.0 .3 Mozilla Firefox 2.0 .10 Mozilla Firefox 2.0 .1 Mozilla Firefox 2.0.0.2 Mozilla Firefox 2.0.0.11 |
| Not Vulnerable: | |
Discussion
Mozilla Firefox 'Basic Realm' Basic Authentication Header Spoofing Vulnerability
Mozilla Firefox is prone to a domain-spoofing vulnerability that allows an attacker to spoof an HTTP basic authentication dialog.
Attackers may exploit this vulnerability via a malicious webpage to spoof the origin of an HTTP basic authentication dialog that the victim may trust. Attackers may find this issue useful in phishing or other attacks that rely on content spoofing.
Firefox 2.0.0.11 is vulnerable; other versions may also be affected.
Mozilla Firefox is prone to a domain-spoofing vulnerability that allows an attacker to spoof an HTTP basic authentication dialog.
Attackers may exploit this vulnerability via a malicious webpage to spoof the origin of an HTTP basic authentication dialog that the victim may trust. Attackers may find this issue useful in phishing or other attacks that rely on content spoofing.
Firefox 2.0.0.11 is vulnerable; other versions may also be affected.
Exploit / POC
Solution / Fix
Mozilla Firefox 'Basic Realm' Basic Authentication Header Spoofing Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Mozilla Firefox 'Basic Realm' Basic Authentication Header Spoofing Vulnerability
References:
References: