CVE-2006-2785: XSS
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 1.5.0.4 allows user-assisted remote attackers to inject arbitrary web script or HTML by tricking a user into (1) performing a "View Image" on a broken image in which the SRC attribute contains a Javascript URL, or (2) selecting "Show only this frame" on a frame whose SRC attribute contains a Javascript URL.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-2785?
The severity of CVE-2006-2785 is considered moderate due to its potential for user-assisted exploitation.
How do I fix CVE-2006-2785?
To fix CVE-2006-2785, upgrade to Mozilla Firefox version 1.5.0.4 or later.
What specific versions of Firefox are affected by CVE-2006-2785?
CVE-2006-2785 affects Mozilla Firefox versions prior to 1.5.0.4.
What type of attack does CVE-2006-2785 enable?
CVE-2006-2785 enables a cross-site scripting (XSS) attack through user-assisted actions.
How can attackers exploit CVE-2006-2785?
Attackers can exploit CVE-2006-2785 by tricking users into interacting with crafted image URLs that contain JavaScript.