PT-2006-3703 · Mozilla+2 · Firefox+2

Paul Nickerson

·

Published

2006-06-02

·

Updated

2018-10-18

·

CVE-2006-2784

CVSS v2.0

5.1

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 1.5.0.4
Description The issue allows remote user-assisted attackers to execute privileged code by tricking a user into installing missing plugins and selecting the "Manual Install" button, then using nested javascript: URLs. This would not cross privilege boundaries if the user installs malicious software from the attacker-controlled site.
Recommendations For versions prior to 1.5.0.4, update to version 1.5.0.4 or later to resolve the issue. As a temporary workaround, consider avoiding the use of the "Manual Install" button for plugin installation until a patch is applied. Restrict access to untrusted websites to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2006-2784
DSA-1118
DSA-1120
DSA-1134-1
HPSBUX02153
RHSA-2006:0578
RHSA-2006:0609
RHSA-2006:0610
RHSA-2006:0611
RHSA-2006_0609
RHSA-2006_0610
RHSA-2006_0611

Affected Products

Hp-Ux
Firefox
Red Hat