CVE-2006-4569: XSS
Published Sep 15, 2006
·Updated
The popup blocker in Mozilla Firefox before 1.5.0.7 opens the "blocked popups" display in the context of the Location bar instead of the subframe from which the popup originated, which might make it easier for remote user-assisted attackers to conduct cross-site scripting (XSS) attacks.
Affected Software
1 affected component
Mozilla Firefox<=1.5.0.6
Remediation
Patch Available
Event History
Sep 15, 2006
CVE Published
07:07 PM
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-4569?
CVE-2006-4569 is considered a medium severity vulnerability affecting older versions of Mozilla Firefox.
2
How do I fix CVE-2006-4569?
To mitigate CVE-2006-4569, upgrade to Mozilla Firefox version 1.5.0.7 or later.
3
What type of attack does CVE-2006-4569 allow?
CVE-2006-4569 could potentially allow attackers to conduct cross-site scripting (XSS) attacks.
4
Which versions of Mozilla Firefox are affected by CVE-2006-4569?
CVE-2006-4569 affects Mozilla Firefox versions prior to 1.5.0.7.
5
What is the impact of exploiting CVE-2006-4569?
Exploitation of CVE-2006-4569 may lead to unauthorized actions being taken in the context of the user's session.