Mozilla · Mozilla Firefox · CVE-2006-0496
**Name of the Vulnerable Software and Affected Versions**
Mozilla versions prior to 1.7.12
Mozilla Firefox versions prior to 1.0.7
Netscape versions prior to 8.1
**Description**
A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML via the `-moz-binding` CSS property. This property does not require the style sheet to have the same origin as the web page. The issue has been demonstrated by the compromise of a large number of LiveJournal accounts.
**Recommendations**
For Mozilla versions prior to 1.7.12, update to a version that fixes this issue.
For Mozilla Firefox versions prior to 1.0.7, update to a version that fixes this issue.
For Netscape versions prior to 8.1, update to a version that fixes this issue.
As a temporary workaround, consider disabling the use of the `-moz-binding` CSS property until a patch is available.