PT-2006-3703 · Mozilla+2 · Firefox+2

Paul Nickerson

·

Publicado

2006-06-02

·

Atualizado

2018-10-18

·

CVE-2006-2784

CVSS v2.0

5.1

Média

VetorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 1.5.0.4
Description The issue allows remote user-assisted attackers to execute privileged code by tricking a user into installing missing plugins and selecting the "Manual Install" button, then using nested javascript: URLs. This would not cross privilege boundaries if the user installs malicious software from the attacker-controlled site.
Recommendations For versions prior to 1.5.0.4, update to version 1.5.0.4 or later to resolve the issue. As a temporary workaround, consider avoiding the use of the "Manual Install" button for plugin installation until a patch is applied. Restrict access to untrusted websites to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2006-2784
DSA-1118
DSA-1120
DSA-1134-1
HPSBUX02153
RHSA-2006:0578
RHSA-2006:0609
RHSA-2006:0610
RHSA-2006:0611
RHSA-2006_0609
RHSA-2006_0610
RHSA-2006_0611

Produtos afetados

Hp-Ux
Firefox
Red Hat