PT-2006-6867 · Apple · Safari

Publicado

2006-12-03

·

Atualizado

2008-09-05

·

CVE-2006-6238

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apple Safari version 2.0.4
Description The issue concerns the AutoFill feature, which does not properly verify the visibility of automatically populated form fields to the user. This allows remote attackers to obtain sensitive information, such as usernames and passwords, via input fields of zero width.
Recommendations For Apple Safari version 2.0.4, consider disabling the AutoFill feature as a temporary workaround until a patch is available. Restrict access to sensitive information by avoiding the use of AutoFill for secure form fields.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-6238

Produtos afetados

Safari