CVE Database
/

CVE-2006-0496

Back to search

CVE-2006-0496

Published: Feb 1, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Cross-site scripting (XSS) vulnerability in Mozilla 1.7.12 and possibly earlier, Mozilla Firefox 1.0.7 and possibly earlier, and Netscape 8.1 and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the -moz-binding (Cascading Style Sheets) CSS property, which does not require that the style sheet have the same origin as the web page, as demonstrated by the compromise of a large number of LiveJournal accounts.

VendorProductVersions

n/a

n/a

affected
n/a

References

1015563
vdb-entry
x_refsource_SECTRACK
mozilla-mozbinding-xss(24427)
vdb-entry
x_refsource_XF
ADV-2006-0403
vdb-entry
x_refsource_VUPEN
16427
vdb-entry
x_refsource_BID
1015553
vdb-entry
x_refsource_SECTRACK
20060128 -moz-binding CSS property: more XSS fun
mailing-list
x_refsource_FULLDISC
22924
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now