CVE-2006-4568: XSS
Mozilla Firefox before 1.5.0.7 and SeaMonkey before 1.0.5 allows remote attackers to bypass the security model and inject content into the sub-frame of another site via targetWindow.frames[n].document.open(), which facilitates spoofing and other attacks.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-4568?
CVE-2006-4568 is classified as a moderate severity vulnerability.
What does CVE-2006-4568 allow attackers to do?
CVE-2006-4568 allows remote attackers to inject content into the sub-frame of another site, leading to spoofing and related attacks.
Which versions of software are affected by CVE-2006-4568?
CVE-2006-4568 affects Mozilla Firefox versions before 1.5.0.7 and SeaMonkey versions before 1.0.5.
How do I fix CVE-2006-4568?
To mitigate CVE-2006-4568, upgrade to Mozilla Firefox version 1.5.0.7 or later and SeaMonkey version 1.0.5 or later.
What kind of attacks can CVE-2006-4568 facilitate?
CVE-2006-4568 can facilitate spoofing attacks and potentially other security issues due to its ability to bypass the security model.