{
    "CVE_data_meta": {
        "ASSIGNER": "cve@mitre.org",
        "ID": "CVE-2006-6077",
        "STATE": "PUBLIC"
    },
    "affects": {
        "vendor": {
            "vendor_data": [
                {
                    "product": {
                        "product_data": [
                            {
                                "product_name": "n/a",
                                "version": {
                                    "version_data": [
                                        {
                                            "version_value": "n/a"
                                        }
                                    ]
                                }
                            }
                        ]
                    },
                    "vendor_name": "n/a"
                }
            ]
        }
    },
    "data_format": "MITRE",
    "data_type": "CVE",
    "data_version": "4.0",
    "description": {
        "description_data": [
            {
                "lang": "eng",
                "value": "The (1) Password Manager in Mozilla Firefox 2.0, and 1.5.0.8 and earlier; and the (2) Passcard Manager in Netscape 8.1.2 and possibly other versions, do not properly verify that an ACTION URL in a FORM element containing a password INPUT element matches the web site for which the user stored a password, which allows remote attackers to obtain passwords via a password INPUT element on a different web page located on the web site intended for this password."
            }
        ]
    },
    "problemtype": {
        "problemtype_data": [
            {
                "description": [
                    {
                        "lang": "eng",
                        "value": "n/a"
                    }
                ]
            }
        ]
    },
    "references": {
        "reference_data": [
            {
                "name": "RHSA-2007:0078",
                "refsource": "REDHAT",
                "url": "http://www.redhat.com/support/errata/RHSA-2007-0078.html"
            },
            {
                "name": "http://www.info-svc.com/news/11-21-2006/rcsr1/",
                "refsource": "MISC",
                "url": "http://www.info-svc.com/news/11-21-2006/rcsr1/"
            },
            {
                "name": "oval:org.mitre.oval:def:10031",
                "refsource": "OVAL",
                "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10031"
            },
            {
                "name": "24395",
                "refsource": "SECUNIA",
                "url": "http://secunia.com/advisories/24395"
            },
            {
                "name": "20070226 rPSA-2007-0040-1 firefox",
                "refsource": "BUGTRAQ",
                "url": "http://www.securityfocus.com/archive/1/461336/100/0/threaded"
            },
            {
                "name": "24328",
                "refsource": "SECUNIA",
                "url": "http://secunia.com/advisories/24328"
            },
            {
                "name": "RHSA-2007:0108",
                "refsource": "REDHAT",
                "url": "http://www.redhat.com/support/errata/RHSA-2007-0108.html"
            },
            {
                "name": "GLSA-200703-04",
                "refsource": "GENTOO",
                "url": "http://security.gentoo.org/glsa/glsa-200703-04.xml"
            },
            {
                "name": "20061123 Re: Big Flaw in Firefox 2: Password Manager Bug Exposes Passwords",
                "refsource": "BUGTRAQ",
                "url": "http://www.securityfocus.com/archive/1/452440/100/0/threaded"
            },
            {
                "name": "GLSA-200703-08",
                "refsource": "GENTOO",
                "url": "http://www.gentoo.org/security/en/glsa/glsa-200703-08.xml"
            },
            {
                "name": "23046",
                "refsource": "SECUNIA",
                "url": "http://secunia.com/advisories/23046"
            },
            {
                "name": "24384",
                "refsource": "SECUNIA",
                "url": "http://secunia.com/advisories/24384"
            },
            {
                "name": "20061123 Password Flaw also in Firefox 1.5.08. Was: Big Flaw in Firefox 2: Password Manager Bug Exposes Passwords",
                "refsource": "BUGTRAQ",
                "url": "http://www.securityfocus.com/archive/1/452431/100/0/threaded"
            },
            {
                "name": "20061221 Re: critical Flaw in Firefox 2.0.0.1 allows to steal the user passwords with a videoclip",
                "refsource": "BUGTRAQ",
                "url": "http://www.securityfocus.com/archive/1/455073/100/0/threaded"
            },
            {
                "name": "24457",
                "refsource": "SECUNIA",
                "url": "http://secunia.com/advisories/24457"
            },
            {
                "name": "firefox-passwordmgr-information-disclosure(30470)",
                "refsource": "XF",
                "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/30470"
            },
            {
                "name": "24343",
                "refsource": "SECUNIA",
                "url": "http://secunia.com/advisories/24343"
            },
            {
                "name": "DSA-1336",
                "refsource": "DEBIAN",
                "url": "http://www.debian.org/security/2007/dsa-1336"
            },
            {
                "name": "HPSBUX02153",
                "refsource": "HP",
                "url": "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742"
            },
            {
                "name": "1017271",
                "refsource": "SECTRACK",
                "url": "http://securitytracker.com/id?1017271"
            },
            {
                "name": "http://www.mozilla.org/security/announce/2007/mfsa2007-02.html",
                "refsource": "CONFIRM",
                "url": "http://www.mozilla.org/security/announce/2007/mfsa2007-02.html"
            },
            {
                "name": "ADV-2007-0718",
                "refsource": "VUPEN",
                "url": "http://www.vupen.com/english/advisories/2007/0718"
            },
            {
                "name": "20061220 critical Flaw in Firefox 2.0.0.1 allows to steal the user passwords with a videoclip",
                "refsource": "BUGTRAQ",
                "url": "http://www.securityfocus.com/archive/1/454982/100/0/threaded"
            },
            {
                "name": "24650",
                "refsource": "SECUNIA",
                "url": "http://secunia.com/advisories/24650"
            },
            {
                "name": "USN-428-1",
                "refsource": "UBUNTU",
                "url": "http://www.ubuntu.com/usn/usn-428-1"
            },
            {
                "name": "24320",
                "refsource": "SECUNIA",
                "url": "http://secunia.com/advisories/24320"
            },
            {
                "name": "25588",
                "refsource": "SECUNIA",
                "url": "http://secunia.com/advisories/25588"
            },
            {
                "name": "https://issues.rpath.com/browse/RPL-1103",
                "refsource": "CONFIRM",
                "url": "https://issues.rpath.com/browse/RPL-1103"
            },
            {
                "name": "SUSE-SA:2007:019",
                "refsource": "SUSE",
                "url": "http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html"
            },
            {
                "name": "20061123 Re: Password Flaw also in Firefox 1.5.08. Was: Big Flaw in Firefox 2: Password Manager Bug Exposes Passwords",
                "refsource": "BUGTRAQ",
                "url": "http://www.securityfocus.com/archive/1/452463/100/0/threaded"
            },
            {
                "name": "20070303 rPSA-2007-0040-3 firefox thunderbird",
                "refsource": "BUGTRAQ",
                "url": "http://www.securityfocus.com/archive/1/461809/100/0/threaded"
            },
            {
                "name": "SUSE-SA:2007:022",
                "refsource": "SUSE",
                "url": "http://www.novell.com/linux/security/advisories/2007_22_mozilla.html"
            },
            {
                "name": "24293",
                "refsource": "SECUNIA",
                "url": "http://secunia.com/advisories/24293"
            },
            {
                "name": "24238",
                "refsource": "SECUNIA",
                "url": "http://secunia.com/advisories/24238"
            },
            {
                "name": "24393",
                "refsource": "SECUNIA",
                "url": "http://secunia.com/advisories/24393"
            },
            {
                "name": "24342",
                "refsource": "SECUNIA",
                "url": "http://secunia.com/advisories/24342"
            },
            {
                "name": "24287",
                "refsource": "SECUNIA",
                "url": "http://secunia.com/advisories/24287"
            },
            {
                "name": "20061122 Big Flaw in Firefox 2: Password Manager Bug Exposes Passwords",
                "refsource": "BUGTRAQ",
                "url": "http://www.securityfocus.com/archive/1/452382/100/0/threaded"
            },
            {
                "name": "20061222 Re[2]: critical Flaw in Firefox 2.0.0.1 allows to steal the user passwords with a videoclip",
                "refsource": "BUGTRAQ",
                "url": "http://www.securityfocus.com/archive/1/455148/100/0/threaded"
            },
            {
                "name": "23108",
                "refsource": "SECUNIA",
                "url": "http://secunia.com/advisories/23108"
            },
            {
                "name": "21240",
                "refsource": "BID",
                "url": "http://www.securityfocus.com/bid/21240"
            },
            {
                "name": "https://bugzilla.mozilla.org/show_bug.cgi?id=360493",
                "refsource": "CONFIRM",
                "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=360493"
            },
            {
                "name": "22694",
                "refsource": "BID",
                "url": "http://www.securityfocus.com/bid/22694"
            },
            {
                "name": "SSRT061181",
                "refsource": "HP",
                "url": "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742"
            },
            {
                "name": "FEDORA-2007-281",
                "refsource": "FEDORA",
                "url": "http://fedoranews.org/cms/node/2713"
            },
            {
                "name": "RHSA-2007:0097",
                "refsource": "REDHAT",
                "url": "http://www.redhat.com/support/errata/RHSA-2007-0097.html"
            },
            {
                "name": "FEDORA-2007-293",
                "refsource": "FEDORA",
                "url": "http://fedoranews.org/cms/node/2728"
            },
            {
                "name": "20070301-01-P",
                "refsource": "SGI",
                "url": "ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc"
            },
            {
                "name": "24205",
                "refsource": "SECUNIA",
                "url": "http://secunia.com/advisories/24205"
            },
            {
                "name": "https://issues.rpath.com/browse/RPL-1081",
                "refsource": "CONFIRM",
                "url": "https://issues.rpath.com/browse/RPL-1081"
            },
            {
                "name": "24333",
                "refsource": "SECUNIA",
                "url": "http://secunia.com/advisories/24333"
            },
            {
                "name": "ADV-2006-4662",
                "refsource": "VUPEN",
                "url": "http://www.vupen.com/english/advisories/2006/4662"
            },
            {
                "name": "MDKSA-2007:050",
                "refsource": "MANDRIVA",
                "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2007:050"
            },
            {
                "name": "24290",
                "refsource": "SECUNIA",
                "url": "http://secunia.com/advisories/24290"
            },
            {
                "name": "RHSA-2007:0077",
                "refsource": "REDHAT",
                "url": "http://rhn.redhat.com/errata/RHSA-2007-0077.html"
            },
            {
                "name": "20070202-01-P",
                "refsource": "SGI",
                "url": "ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc"
            },
            {
                "name": "SSA:2007-066-05",
                "refsource": "SLACKWARE",
                "url": "http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.338131"
            },
            {
                "name": "RHSA-2007:0079",
                "refsource": "REDHAT",
                "url": "http://www.redhat.com/support/errata/RHSA-2007-0079.html"
            },
            {
                "name": "http://www.info-svc.com/news/11-21-2006/",
                "refsource": "MISC",
                "url": "http://www.info-svc.com/news/11-21-2006/"
            },
            {
                "name": "24437",
                "refsource": "SECUNIA",
                "url": "http://secunia.com/advisories/24437"
            }
        ]
    }
}