CVE-2006-4568

CVSS v2.0 4.3 (Medium)
43% Progress
EPSS 2.55 % (90th)
2.55% Progress
Affected Products 2
Advisories 6

Mozilla Firefox before 1.5.0.7 and SeaMonkey before 1.0.5 allows remote attackers to bypass the security model and inject content into the sub-frame of another site via targetWindow.frames[n].document.open(), which facilitates spoofing and other attacks.

Weaknesses
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Related CVEs
CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2006-09-15 19:07:00
(18 years ago)
Updated Date
2018-10-17 21:37:54
(6 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mozilla Firefox 1.5.0.6 and prior versions cpe:2.3:a:mozilla:firefox <= 1.5.0.6
  Mozilla Seamonkey 1.0.4 and prior versions cpe:2.3:a:mozilla:seamonkey <= 1.0.4
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...