Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Ctho

#51155of 53,622
4.3Total CVSS
Vulnerabilities · 1
PT-2006-1561
4.3
2006-02-01
Mozilla · Mozilla Firefox · CVE-2006-0496
**Name of the Vulnerable Software and Affected Versions** Mozilla versions prior to 1.7.12 Mozilla Firefox versions prior to 1.0.7 Netscape versions prior to 8.1 **Description** A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML via the `-moz-binding` CSS property. This property does not require the style sheet to have the same origin as the web page. The issue has been demonstrated by the compromise of a large number of LiveJournal accounts. **Recommendations** For Mozilla versions prior to 1.7.12, update to a version that fixes this issue. For Mozilla Firefox versions prior to 1.0.7, update to a version that fixes this issue. For Netscape versions prior to 8.1, update to a version that fixes this issue. As a temporary workaround, consider disabling the use of the `-moz-binding` CSS property until a patch is available.