CVE-2006-0496
Title: Mozilla Firefox Cross-Site Scripting (XSS)
Proof Of Concept
PoC Available for CVE-2006-0496
Vulnerability Summary
CVE-2006-0496: Cross-site scripting (XSS) vulnerability in Mozilla 1.7.12 and possibly earlier, Mozilla Firefox 1.0.7 and possibly earlier, and Netscape 8.1 and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the -moz-binding (Cascading Style Sheets) CSS property, which does not require that the style sheet have the same origin as the web page, as demonstrated by the compromise of a large number of LiveJournal accounts.
Impacted Vendors
Reference Links
AV:N/AC:M/Au:N/C:N/I:P/A:N
Associated Attack Patterns (CAPEC)
Total: PatternsNo specific attack patterns mapped.
CVE-2006-0496 Exploits & PoCs (Proof Of Concept)
Vulnerability data updated via NVD.
Vulnerability data or affected products updated.
Vulnerability first announced in NVD.
Attack Vector Matrix
AV:N/AC:M/Au:N/C:N/I:P/A:N
Affected Stack
No specific products linked.