CVE-2006-6077 Affecting mozilla package, versions [,1.5.0.9)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
8.05% (95th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-MOZILLA-2378773
  • published26 Jan 2022
  • disclosed24 Nov 2006
  • creditUnknown

Introduced: 24 Nov 2006

CVE-2006-6077  (opens in a new tab)

How to fix?

Upgrade mozilla to version 1.5.0.9 or higher.

Overview

The (1) Password Manager in Mozilla Firefox 2.0, and 1.5.0.8 and earlier; and the (2) Passcard Manager in Netscape 8.1.2 and possibly other versions, do not properly verify that an ACTION URL in a FORM element containing a password INPUT element matches the web site for which the user stored a password, which allows remote attackers to obtain passwords via a password INPUT element on a different web page located on the web site intended for this password.

References

CVSS Scores

version 3.1