CVE-2006-2784: Medium severity Mozilla Firefox vulnerability
The PLUGINSPAGE functionality in Mozilla Firefox before 1.5.0.4 allows remote user-assisted attackers to execute privileged code by tricking a user into installing missing plugins and selecting the "Manual Install" button, then using nested javascript: URLs. NOTE: the manual install button is used for downloading software from a remote web site, so this issue would not cross privilege boundaries if the user progresses to the point of installing malicious software from the attacker-controlled site.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-2784?
CVE-2006-2784 is classified as a moderate severity vulnerability.
How do I fix CVE-2006-2784?
To fix CVE-2006-2784, upgrade Mozilla Firefox to version 1.5.0.4 or later.
What impact does CVE-2006-2784 have on users?
CVE-2006-2784 allows remote attackers to execute privileged code through user-assisted actions.
What versions of Firefox are affected by CVE-2006-2784?
CVE-2006-2784 affects Mozilla Firefox versions before 1.5.0.4.
Is there a workaround for CVE-2006-2784?
There are no specific workarounds for CVE-2006-2784; updating Firefox is the recommended action.