Vulnerability Name: | CVE-2007-0802 (CCN-32585) | ||||||||
Assigned: | 2007-02-06 | ||||||||
Published: | 2007-02-06 | ||||||||
Updated: | 2022-02-26 | ||||||||
Summary: | Mozilla Firefox 2.0.0.1 allows remote attackers to bypass the Phishing Protection mechanism by adding certain characters to the end of the domain name, as demonstrated by the "." and "/" characters, which is not caught by the Phishing List blacklist filter. | ||||||||
CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 6.4 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N) 5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N/E:U/RL:U/RC:C)
2.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N/E:U/RL:U/RC:C)
| ||||||||
Vulnerability Type: | CWE-20 | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Tue Feb 06 2007 - 07:05:19 CST Firefox 2.0.0.1 and Opera 9.10 Anty Fraud/Phishing Protection bypass. Source: FULLDISC Type: Broken Link 20070418 Firefox 2.0.0.3 Phishing Protection Bypass Vulnerability Source: MITRE Type: CNA CVE-2006-6970 Source: MITRE Type: CNA CVE-2007-0802 Source: MISC Type: Broken Link, Exploit, Vendor Advisory http://kaneda.bohater.net/security/20070111-firefox_2.0.0.1_bypass_phishing_protection.php Source: OSVDB Type: Broken Link 33705 Source: CCN Type: OSVDB ID: 33705 Mozilla Firefox Phishing Protection Crafted URL Bypass Source: CCN Type: OSVDB ID: 34927 Opera Fraud Protection Crafted Domain Bypass Source: BUGTRAQ Type: Broken Link, Third Party Advisory, VDB Entry 20070206 Firefox 2.0.0.1 and Opera 9.10 Anty Fraud/Phishing Protection bypass. Source: CCN Type: Mozilla Bugzilla Bug 367538 Firefox 2.0.0.1 Phishing Protection bypass Source: MISC Type: Issue Tracking, Third Party Advisory https://bugzilla.mozilla.org/show_bug.cgi?id=367538 Source: XF Type: UNKNOWN firefox-phishingprotection-security-bypass(32585) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |