The (1) Password Manager in Mozilla Firefox 2.0, and 1.5.0.8...
Vulnerability Description
The (1) Password Manager in Mozilla Firefox 2.0, and 1.5.0.8 and earlier; and the (2) Passcard Manager in Netscape 8.1.2 and possibly other versions, do not properly verify that an ACTION URL in a FORM element containing a password INPUT element matches the web site for which the user stored a password, which allows remote attackers to obtain passwords via a password INPUT element on a different web page located on the web site intended for this password.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-6077
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.redhat.com/support/errata/RHSA-2007-0078.html
- http://www.info-svc.com/news/11-21-2006/rcsr1/
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10031
- http://secunia.com/advisories/24395
- http://www.securityfocus.com/archive/1/461336/100/0/threaded
- http://secunia.com/advisories/24328
- http://www.redhat.com/support/errata/RHSA-2007-0108.html
- http://security.gentoo.org/glsa/glsa-200703-04.xml
- http://www.securityfocus.com/archive/1/452440/100/0/threaded
- http://www.gentoo.org/security/en/glsa/glsa-200703-08.xml
- http://secunia.com/advisories/23046
- http://secunia.com/advisories/24384
- http://www.securityfocus.com/archive/1/452431/100/0/threaded
- http://www.securityfocus.com/archive/1/455073/100/0/threaded
- http://secunia.com/advisories/24457
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30470
- http://secunia.com/advisories/24343
- http://www.debian.org/security/2007/dsa-1336
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742
- http://securitytracker.com/id?1017271
- http://www.mozilla.org/security/announce/2007/mfsa2007-02.html
- http://www.vupen.com/english/advisories/2007/0718
- http://www.securityfocus.com/archive/1/454982/100/0/threaded
- http://secunia.com/advisories/24650
- http://www.ubuntu.com/usn/usn-428-1
- http://secunia.com/advisories/24320
- http://secunia.com/advisories/25588
- https://issues.rpath.com/browse/RPL-1103
- http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html
- http://www.securityfocus.com/archive/1/452463/100/0/threaded
- http://www.securityfocus.com/archive/1/461809/100/0/threaded
- http://www.novell.com/linux/security/advisories/2007_22_mozilla.html
- http://secunia.com/advisories/24293
- http://secunia.com/advisories/24238
- http://secunia.com/advisories/24393
- http://secunia.com/advisories/24342
- http://secunia.com/advisories/24287
- http://www.securityfocus.com/archive/1/452382/100/0/threaded
- http://www.securityfocus.com/archive/1/455148/100/0/threaded
- http://secunia.com/advisories/23108
- http://www.securityfocus.com/bid/21240
- https://bugzilla.mozilla.org/show_bug.cgi?id=360493
- http://www.securityfocus.com/bid/22694
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742
- http://fedoranews.org/cms/node/2713
- http://www.redhat.com/support/errata/RHSA-2007-0097.html
- http://fedoranews.org/cms/node/2728
- ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc
- http://secunia.com/advisories/24205
- https://issues.rpath.com/browse/RPL-1081
- http://secunia.com/advisories/24333
- http://www.vupen.com/english/advisories/2006/4662
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:050
- http://secunia.com/advisories/24290
- http://rhn.redhat.com/errata/RHSA-2007-0077.html
- ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc
- http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.338131
- http://www.redhat.com/support/errata/RHSA-2007-0079.html
- http://www.info-svc.com/news/11-21-2006/
- http://secunia.com/advisories/24437
More from mozilla
View All →Affected Vendor
mozilla
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.