CVE-2006-6238
N/A
N/A
Summary
The AutoFill feature in Apple Safari 2.0.4 does not properly verify that all automatically populated form fields are visible to the user, which allows remote attackers to obtain sensitive information, such as usernames and passwords, via input fields of zero width, a variant of CVE-2006-6077.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://tearesolutions.com/2006/11/how_to_steal_passwords_from_safaris_autofill.html
- http://secunia.com/advisories/23066
- http://www.securityfocus.com/bid/21329
References
- http://tearesolutions.com/2006/11/how_to_steal_passwords_from_safaris_autofill.html
- http://secunia.com/advisories/23066
- http://www.securityfocus.com/bid/21329
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.