CVE-2006-6077

Deferred
Published: 24 Nov 2006, 17:00
Last modified:07 Aug 2024, 20:12

Vulnerability Summary

Overall Risk (default)
medium
31/100
CVSS Score
5 MEDIUM
v2.0 (nvd)
EPSS Score
3.06% LOW
3% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
5 found
Dark Web
Not detected

Timeline

24 Nov 2006, 17:00
Published
Vulnerability first disclosed
07 Aug 2024, 20:12
Last Modified
Vulnerability information updated

Description

The (1) Password Manager in Mozilla Firefox 2.0, and 1.5.0.8 and earlier; and the (2) Passcard Manager in Netscape 8.1.2 and possibly other versions, do not properly verify that an ACTION URL in a FORM element containing a password INPUT element matches the web site for which the user stored a password, which allows remote attackers to obtain passwords via a password INPUT element on a different web page located on the web site intended for this password.

CVSS Metrics

  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 3.06% Percentile: 87%

Affected Systems

  • UnknownFirefox

    ≤ 1.5.0.8 | 1.5 | 1.5:beta1 | 1.5:beta2 | 1.5.0.1 | 1.5.0.2 | 1.5.0.3 | 1.5.0.4 | 1.5.0.5 | 1.5.0.6 | 1.5.0.7 | 2.0

  • netscapenavigator

    8.1.2

References (59)