CVE-2007-0802
 
Severity Score
6.4
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Mozilla Firefox 2.0.0.1 allows remote attackers to bypass the Phishing Protection mechanism by adding certain characters to the end of the domain name, as demonstrated by the "." and "/" characters, which is not caught by the Phishing List blacklist filter.
Mozilla Firefox 2.0.0.1 permite a atacantes remotos evitar el mecanismo de Protección de Phising añadiendo caracteres concretos al final del nombre de dominio, como se demuestra con los caractere "." y "/", que no se capturan por el filtro de lista negra Lista de Phising.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2007-02-07 CVE Reserved
- 2007-02-07 CVE Published
- 2023-12-12 EPSS Updated
- 2024-08-07 CVE Updated
- 2024-08-07 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-20: Improper Input Validation
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://archives.neohapsis.com/archives/fulldisclosure/2007-04/0516.html | Broken Link | |
http://osvdb.org/33705 | Broken Link | |
http://www.securityfocus.com/archive/1/459265/100/0/threaded | Broken Link | |
https://bugzilla.mozilla.org/show_bug.cgi?id=367538 | Issue Tracking |
URL | Date | SRC |
---|---|---|
http://kaneda.bohater.net/security/20070111-firefox_2.0.0.1_bypass_phishing_protection.php | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mozilla Search vendor "Mozilla" | Firefox Search vendor "Mozilla" for product "Firefox" | 2.0.0.1 Search vendor "Mozilla" for product "Firefox" and version "2.0.0.1" | - |
Affected
| ||||||
Opera Search vendor "Opera" | Opera Browser Search vendor "Opera" for product "Opera Browser" | 9.10 Search vendor "Opera" for product "Opera Browser" and version "9.10" | - |
Affected
|