PT-2006-6867 · Apple · Safari
Published
2006-12-03
·
Updated
2008-09-05
·
CVE-2006-6238
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apple Safari version 2.0.4
Description
The issue concerns the AutoFill feature, which does not properly verify the visibility of automatically populated form fields to the user. This allows remote attackers to obtain sensitive information, such as usernames and passwords, via input fields of zero width.
Recommendations
For Apple Safari version 2.0.4, consider disabling the AutoFill feature as a temporary workaround until a patch is available. Restrict access to sensitive information by avoiding the use of AutoFill for secure form fields.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Safari