← Back to CVE List
Vulnerability Intelligence Report

CVE-2006-6984

Cross-domain vulnerability in GreenBrowser 3.4.0622 allows remote attackers to access restricted information from other domains via an object tag with a data parameter that references a link on the attacker's originating site that specifies a Location HTTP header that references the target site, which then makes that content available through the outerHTML attribute of the object, a similar vulnerability to CVE-2006-3280.

No Active Exploit Signals
CVSS Base Score
5.0
MEDIUM
EPSS Probability:1.08%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Affected Products & Versions

Vendor Product Affected Versions
more_quick_tools greenbrowser 3.4.0622

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
1.076%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2007-02-08T00:00:00
Published2007-02-09T01:00:00
Patch Date2006-06-27
Last Updated2024-08-07T20:50:04

LINK COPIED TO CLIPBOARD