CVE-2008-1238

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
27/03/2008
Last modified:
09/04/2025

Description

Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9, when generating the HTTP Referer header, does not list the entire URL when it contains Basic Authentication credentials without a username, which makes it easier for remote attackers to bypass application protection mechanisms that rely on Referer headers, such as with some Cross-Site Request Forgery (CSRF) mechanisms.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* 2.0.0.12 (including)
cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:* 1.1.8 (including)


References to Advisories, Solutions, and Tools