CVE-2006-0884
Thunderbird < 1.0.7 - Information Disclosure via IFRAME SRC JavaScript URI
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-0884. PoCs published by Georgi Guninski.
AI-analyzed exploit summary This exploit demonstrates a script-execution vulnerability in Mozilla products (Thunderbird, SeaMonkey, Mozilla Suite) where malicious JavaScript in an IFRAME can execute even if JavaScript is disabled. The PoC includes examples for both arbitrary script execution and a denial-of-service (application crash).
Description
The WYSIWYG rendering engine ("rich mail" editor) in Mozilla Thunderbird 1.0.7 and earlier allows user-assisted attackers to bypass javascript security settings and obtain sensitive information or cause a crash via an e-mail containing a javascript URI in the SRC attribute of an IFRAME tag, which is executed when the user edits the e-mail.
Exploits (1)
This exploit demonstrates a script-execution vulnerability in Mozilla products (Thunderbird, SeaMonkey, Mozilla Suite) where malicious JavaScript in an IFRAME can execute even if JavaScript is disabled. The PoC includes examples for both arbitrary script execution and a denial-of-service (application crash).