PT-2006-6867 · Apple · Safari
Publicado
2006-12-03
·
Atualizado
2008-09-05
·
CVE-2006-6238
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apple Safari version 2.0.4
Description
The issue concerns the AutoFill feature, which does not properly verify the visibility of automatically populated form fields to the user. This allows remote attackers to obtain sensitive information, such as usernames and passwords, via input fields of zero width.
Recommendations
For Apple Safari version 2.0.4, consider disabling the AutoFill feature as a temporary workaround until a patch is available. Restrict access to sensitive information by avoiding the use of AutoFill for secure form fields.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Safari