PT-2006-6867 · Apple · Safari

Published

2006-12-03

·

Updated

2008-09-05

·

CVE-2006-6238

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apple Safari version 2.0.4
Description The issue concerns the AutoFill feature, which does not properly verify the visibility of automatically populated form fields to the user. This allows remote attackers to obtain sensitive information, such as usernames and passwords, via input fields of zero width.
Recommendations For Apple Safari version 2.0.4, consider disabling the AutoFill feature as a temporary workaround until a patch is available. Restrict access to sensitive information by avoiding the use of AutoFill for secure form fields.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-6238

Affected Products

Safari