CVE-2006-1741: XSS
Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to inject arbitrary Javascript into other sites by (1) "using a modal alert to suspend an event handler while a new page is being loaded", (2) using eval(), and using certain variants involving (3) "new Script;" and (4) using window.proto to extend eval, aka "cross-site JavaScript injection".
Affected Software
Event History
Frequently Asked Questions
What are the potential impacts of CVE-2006-1741?
CVE-2006-1741 allows remote attackers to inject arbitrary JavaScript into other sites, potentially leading to data theft or session hijacking.
Which versions of Mozilla Firefox are affected by CVE-2006-1741?
Mozilla Firefox versions before 1.5, and 1.0.x before 1.0.8 are impacted by CVE-2006-1741.
How can I mitigate CVE-2006-1741?
To mitigate CVE-2006-1741, users should upgrade to Mozilla Firefox version 1.5 or later, or apply the available patches.
Is CVE-2006-1741 present in SeaMonkey or Mozilla Suite?
Yes, CVE-2006-1741 affects SeaMonkey versions before 1.0 and Mozilla Suite versions before 1.7.13.
What should I do if I am using an affected version of Ubuntu Linux related to CVE-2006-1741?
If using an affected version of Ubuntu Linux, upgrade to a version that includes the security fixes for CVE-2006-1741.