CVE-2008-1238

Mozilla Firefox <2.0.0.13 & SeaMonkey <1.1.9 - CSRF

Title source: llm

Description

Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9, when generating the HTTP Referer header, does not list the entire URL when it contains Basic Authentication credentials without a username, which makes it easier for remote attackers to bypass application protection mechanisms that rely on Referer headers, such as with some Cross-Site Request Forgery (CSRF) mechanisms.

References (35)

... and 15 more

Scores

EPSS 0.0542
EPSS Percentile 90.0%

Classification

CWE
CWE-287
Status draft

Affected Products (2)

mozilla/firefox < 2.0.0.12
mozilla/seamonkey < 1.1.8

Timeline

Published Mar 27, 2008
Tracked Since Feb 18, 2026