CVE-2008-1238 describes a vulnerability in Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9 where the HTTP Referer header omits the full URL when it contains Basic Authentication credentials without a username. This flaw could allow remote attackers to bypass application protection mechanisms, such as certain Cross-Site Request Forgery (CSRF) defenses, that rely on accurate Referer headers. With a CVSS score of 5.0, this vulnerability has a low attack complexity and could lead to partial integrity impacts, but does not affect confidentiality or availability. There is no evidence of active exploitation, nor are there publicly available exploit modules or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.0.0.12CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
<= 1.1.8CPE matchmatch criteria | cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.