[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250038

 
 

909

 
 

195843

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2006-6077Date: (C)2006-11-24   (M)2023-12-22


The (1) Password Manager in Mozilla Firefox 2.0, and 1.5.0.8 and earlier; and the (2) Passcard Manager in Netscape 8.1.2 and possibly other versions, do not properly verify that an ACTION URL in a FORM element containing a password INPUT element matches the web site for which the user stored a password, which allows remote attackers to obtain passwords via a password INPUT element on a different web page located on the web site intended for this password.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.0
Exploit Score: 10.0
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: NONE
Availability: NONE
  
Reference:
SECTRACK-1017271
http://www.securityfocus.com/archive/1/archive/1/452382/100/0/threaded
http://www.securityfocus.com/archive/1/archive/1/452431/100/0/threaded
http://www.securityfocus.com/archive/1/archive/1/452440/100/0/threaded
http://www.securityfocus.com/archive/1/archive/1/452463/100/0/threaded
http://www.securityfocus.com/archive/1/archive/1/454982/100/0/threaded
http://www.securityfocus.com/archive/1/archive/1/455073/100/0/threaded
http://www.securityfocus.com/archive/1/archive/1/455148/100/0/threaded
20070202-01-P
http://www.securityfocus.com/archive/1/archive/1/461336/100/0/threaded
20070301-01-P
http://www.securityfocus.com/archive/1/archive/1/461809/100/0/threaded
BID-21240
BID-22694
SECUNIA-23046
SECUNIA-23108
SECUNIA-24205
SECUNIA-24238
SECUNIA-24287
SECUNIA-24290
SECUNIA-24293
SECUNIA-24320
SECUNIA-24328
SECUNIA-24333
SECUNIA-24342
SECUNIA-24343
SECUNIA-24384
SECUNIA-24393
SECUNIA-24395
SECUNIA-24437
SECUNIA-24457
SECUNIA-24650
SECUNIA-25588
ADV-2006-4662
ADV-2007-0718
DSA-1336
FEDORA-2007-281
FEDORA-2007-293
GLSA-200703-04
GLSA-200703-08
HPSBUX02153
MDKSA-2007:050
RHSA-2007:0077
RHSA-2007:0078
RHSA-2007:0079
RHSA-2007:0097
RHSA-2007:0108
SSA:2007-066-05
SUSE-SA:2007:019
SUSE-SA:2007:022
USN-428-1
firefox-passwordmgr-information-disclosure(30470)
http://www.info-svc.com/news/11-21-2006/
http://www.info-svc.com/news/11-21-2006/rcsr1/
http://www.mozilla.org/security/announce/2007/mfsa2007-02.html
https://bugzilla.mozilla.org/show_bug.cgi?id=360493
https://issues.rpath.com/browse/RPL-1081
https://issues.rpath.com/browse/RPL-1103

CPE    13
cpe:/a:mozilla:firefox:1.5.0.4
cpe:/a:mozilla:firefox:1.5.0.3
cpe:/a:mozilla:firefox:1.5:beta2
cpe:/a:mozilla:firefox:1.5.0.2
...

© SecPod Technologies