Vulnerability Description
The AutoFill feature in Apple Safari 2.0.4 does not properly verify that all automatically populated form fields are visible to the user, which allows remote attackers to obtain sensitive information, such as usernames and passwords, via input fields of zero width, a variant of CVE-2006-6077.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apple | Safari | 2.0.4 |
References
- http://secunia.com/advisories/23066Vendor Advisory
- http://tearesolutions.com/2006/11/how_to_steal_passwords_from_safaris_autofill.hExploit
- http://www.securityfocus.com/bid/21329Exploit
- http://secunia.com/advisories/23066Vendor Advisory
- http://tearesolutions.com/2006/11/how_to_steal_passwords_from_safaris_autofill.hExploit
- http://www.securityfocus.com/bid/21329Exploit
FAQ
What is CVE-2006-6238?
CVE-2006-6238 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The AutoFill feature in Apple Safari 2.0.4 does not properly verify that all automatically populated form fields are visible to the user, which allows remote attackers to obtain sensitive information,...
How severe is CVE-2006-6238?
CVE-2006-6238 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-6238?
Check the references section above for vendor advisories and patch information. Affected products include: Apple Safari.