First published: Thu Feb 08 2007(Updated: )
Cross-site scripting (XSS) vulnerability in the "Basic Toolbar Selection" in FCKEditor allows remote attackers to execute arbitrary JavaScript via the javascript: URI in the (1) href or (2) onmouseover attribute of the A HTML tag.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ht Editor |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-6978 is considered a medium severity vulnerability due to the potential for unauthorized JavaScript execution.
To fix CVE-2006-6978, update to the latest version of FCKEditor that addresses this cross-site scripting vulnerability.
CVE-2006-6978 affects FCKEditor versions that include the "Basic Toolbar Selection" functionality.
Yes, CVE-2006-6978 can lead to serious security issues such as session hijacking or data manipulation if exploited.
The attack for CVE-2006-6978 involves injecting malicious JavaScript through the href or onmouseover attributes of A HTML tags.