CVE-2007-5960
Description
Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 sets the Referer header to the window or frame in which script is running, instead of the address of the content that initiated the script, which allows remote attackers to spoof HTTP Referer headers and bypass Referer-based CSRF protection schemes by setting window.location and using a modal alert dialog that causes the wrong Referer to be sent.
Risk Information
Base Score
4.3
MODERATE
Vector
AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
EPSS Score
Exploitation Probability
1.259
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Multiple vulnerabilities affected in Mozilla Firefox (x64) 2.0.0.9 | Windows |
| Multiple vulnerabilities affected in Mozilla_Firefox 2.0.0.9 | Windows |
| Multiple vulnerabilities affected in SeaMonkey 1.1.7 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 2.0 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 2.0.0.1 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 2.0 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 2.0.0.1 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 0.10.1 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 0.8 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 0.9 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 0.9.1 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 0.9.2 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 0.9.3 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.0 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.0.1 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.0.2 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.0.3 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.0.4 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.0.5 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.0.6 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.0.7 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.0.8 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.5 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.5.0.1 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.5.0.10 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.5.0.11 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.5.0.12 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.5.0.2 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.5.0.3 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.5.0.4 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.5.0.5 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.5.0.6 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.5.0.7 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.5.0.8 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.5.0.9 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.5.1 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.5.2 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.5.3 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.5.4 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.5.5 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.5.6 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.5.7 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.5.8 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 2.0.0.2 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 2.0.0.3 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 2.0.0.4 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 2.0.0.5 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 2.0.0.6 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 2.0.0.7 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 2.0.0.8 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 2.0.0.9 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 0.10.1 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 0.8 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 0.9 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 0.9.1 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 0.9.2 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 0.9.3 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 1.0 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 1.0.1 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 1.0.2 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 1.0.3 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 1.0.4 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 1.0.5 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 1.0.6 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 1.0.7 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 1.0.8 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 1.5 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 1.5.0.1 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 1.5.0.10 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 1.5.0.11 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 1.5.0.12 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 1.5.0.2 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 1.5.0.3 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 1.5.0.4 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 1.5.0.5 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 1.5.0.6 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 1.5.0.7 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 1.5.0.8 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 1.5.0.9 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 1.5.1 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 1.5.2 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 1.5.3 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 1.5.4 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 1.5.5 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 1.5.6 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 1.5.7 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 1.5.8 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 2.0.0.2 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 2.0.0.3 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 2.0.0.4 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 2.0.0.5 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 2.0.0.6 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 2.0.0.7 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 2.0.0.8 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 2.0.0.9 | Windows |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-343016 | Mozilla Firefox (x64) (132.0.2) |
| PATCH-343015 | Mozilla Firefox (132.0.2) |
| PATCH-341197 | SeaMonkey (2.53.19) |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234