CVE-2007-0802
Last modified
CVE-2007-0802 is a vulnerability of currently unknown severity. Mozilla Firefox 2.0.0.1 allows remote attackers to bypass the Phishing Protection mechanism by adding certain characters to the end of the domain name, as demonstrated by the "." and "/" characters, which is not caught by the Phishing List blacklist filter.. EPSS estimates a 2.03% chance of exploitation in the next 30 days.
Description
Mozilla Firefox 2.0.0.1 allows remote attackers to bypass the Phishing Protection mechanism by adding certain characters to the end of the domain name, as demonstrated by the "." and "/" characters, which is not caught by the Phishing List blacklist filter.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | 2.0.0.1 |
| Opera | Opera Browser | 9.10 |
References
- http://kaneda.bohater.net/security/20070111-firefox_2.0.0.1_bypass_phishing_protection.phpBroken Link, Exploit, Vendor Advisory
- http://osvdb.org/33705Broken Link
- http://www.securityfocus.com/archive/1/459265/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- https://bugzilla.mozilla.org/show_bug.cgi?id=367538Issue Tracking, Third Party Advisory
- http://kaneda.bohater.net/security/20070111-firefox_2.0.0.1_bypass_phishing_protection.phpBroken Link, Exploit, Vendor Advisory
- http://osvdb.org/33705Broken Link
- http://www.securityfocus.com/archive/1/459265/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- https://bugzilla.mozilla.org/show_bug.cgi?id=367538Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-0802?
How severe is CVE-2007-0802?
How do I fix CVE-2007-0802?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-0796Blue Coat Systems WinProxy 6.1a and 6.0 r1c, and possibly ea…
- CVE-2007-0797PHP remote file inclusion vulnerability in theme/settings.ph…
- CVE-2007-0798Multiple cross-site scripting (XSS) vulnerabilities in Ublog…
- CVE-2007-0799SQL injection vulnerability in badword.asp in Ublog Reload 1…
- CVE-2007-0800Cross-zone vulnerability in Mozilla Firefox 1.5.0.9 consider…
- CVE-2007-0801The nsExternalAppHandler::SetUpTempFile function in Mozilla …
- CVE-2007-0803Multiple buffer overflows in STLport before 5.0.3 allow remo…
- CVE-2007-0804Directory traversal vulnerability in admin/subpages.php in G…
- CVE-2007-0805The ps (/usr/ucb/ps) command on HP Tru64 UNIX 5.1 1885 allow…
- CVE-2007-0806Les News 2.2 allows remote attackers to bypass authenticatio…
- CVE-2007-0807Cross-site scripting (XSS) vulnerability in info.php in flas…
- CVE-2007-0808PHP remote file inclusion vulnerability in Mina Ajans Script…
Are you affected by CVE-2007-0802?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
