CRLF Injection Vulnerability in Mozilla Firefox and SeaMonkey
CVE-2007-2292
Currently unrated
Key Information:
- Vendor
Mozilla
- Vendor
- CVE Published:
- 26 April 2007
What is CVE-2007-2292?
A CRLF injection vulnerability present in the Digest Authentication support of Mozilla Firefox and SeaMonkey allows remote attackers to exploit the system. This occurs through the injection of line feed (LF, %0a) characters in the username field, leading to HTTP request splitting attacks. These attacks enable unauthorized manipulation of HTTP responses, potentially compromising user sessions and leading to further security breaches.