CVE-2006-6978: XSS
Cross-site scripting (XSS) vulnerability in the "Basic Toolbar Selection" in FCKEditor allows remote attackers to execute arbitrary JavaScript via the javascript: URI in the (1) href or (2) onmouseover attribute of the A HTML tag.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-6978?
CVE-2006-6978 is considered a medium severity vulnerability due to the potential for unauthorized JavaScript execution.
How do I fix CVE-2006-6978?
To fix CVE-2006-6978, update to the latest version of FCKEditor that addresses this cross-site scripting vulnerability.
What affects CVE-2006-6978?
CVE-2006-6978 affects FCKEditor versions that include the "Basic Toolbar Selection" functionality.
Can CVE-2006-6978 lead to serious security issues?
Yes, CVE-2006-6978 can lead to serious security issues such as session hijacking or data manipulation if exploited.
What is the nature of the attack for CVE-2006-6978?
The attack for CVE-2006-6978 involves injecting malicious JavaScript through the href or onmouseover attributes of A HTML tags.