Vulnerability Name: | CVE-2006-6970 (CCN-32585) | ||||||||
Assigned: | 2007-02-06 | ||||||||
Published: | 2007-02-06 | ||||||||
Updated: | 2018-10-16 | ||||||||
Summary: | Opera 9.10 Final allows remote attackers to bypass the Fraud Protection mechanism by adding certain characters to the end of a domain name, as demonstrated by the "." and "/" characters, which is not caught by the blacklist filter. | ||||||||
CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 4.2 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:U/RC:C)
2.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N/E:U/RL:U/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Tue Feb 06 2007 - 07:05:19 CST Firefox 2.0.0.1 and Opera 9.10 Anty Fraud/Phishing Protection bypass. Source: MITRE Type: CNA CVE-2006-6970 Source: MITRE Type: CNA CVE-2007-0802 Source: MISC Type: Exploit, Vendor Advisory http://kaneda.bohater.net/security/20061220-opera_9.10_final_bypass_fraud_protection.php Source: OSVDB Type: UNKNOWN 34927 Source: CCN Type: OSVDB ID: 33705 Mozilla Firefox Phishing Protection Crafted URL Bypass Source: CCN Type: OSVDB ID: 34927 Opera Fraud Protection Crafted Domain Bypass Source: BUGTRAQ Type: UNKNOWN 20070206 Firefox 2.0.0.1 and Opera 9.10 Anty Fraud/Phishing Protection bypass. Source: CCN Type: Mozilla Bugzilla Bug 367538 Firefox 2.0.0.1 Phishing Protection bypass Source: XF Type: UNKNOWN firefox-phishingprotection-security-bypass(32585) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |