PT-2006-1561 · Mozilla+1 · Mozilla Firefox+2
Brad Fitzpatrick
+2
·
Publicado
2006-02-01
·
Atualizado
2017-07-20
·
CVE-2006-0496
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Mozilla versions prior to 1.7.12
Mozilla Firefox versions prior to 1.0.7
Netscape versions prior to 8.1
Description
A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML via the
-moz-binding CSS property. This property does not require the style sheet to have the same origin as the web page. The issue has been demonstrated by the compromise of a large number of LiveJournal accounts.Recommendations
For Mozilla versions prior to 1.7.12, update to a version that fixes this issue.
For Mozilla Firefox versions prior to 1.0.7, update to a version that fixes this issue.
For Netscape versions prior to 8.1, update to a version that fixes this issue.
As a temporary workaround, consider disabling the use of the
-moz-binding CSS property until a patch is available.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Firefox
Mozilla Firefox
Netscape