CVE Database
/

CVE-2006-2894

Back to search

CVE-2006-2894

Published: Jun 7, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Mozilla Firefox 1.5.0.4, 2.0.x before 2.0.0.8, Mozilla Suite 1.7.13, Mozilla SeaMonkey 1.0.2 and other versions before 1.1.5, and Netscape 8.1 and earlier allow user-assisted remote attackers to read arbitrary files by tricking a user into typing the characters of the target filename in a text box and using the OnKeyDown, OnKeyPress, and OnKeyUp Javascript keystroke events to change the focus and cause those characters to be inserted into a file upload input control, which can then upload the file when the user submits the form.

VendorProductVersions

n/a

n/a

affected
n/a

References

20071026 rPSA-2007-0225-1 firefox
mailing-list
x_refsource_BUGTRAQ
MDKSA-2006:145
vendor-advisory
x_refsource_MANDRIVA
27414
third-party-advisory
x_refsource_SECUNIA
20071029 FLEA-2007-0062-1 firefox
mailing-list
x_refsource_BUGTRAQ
ADV-2006-2163
vdb-entry
x_refsource_VUPEN
1059
third-party-advisory
x_refsource_SREASON
HPSBUX02153
vendor-advisory
x_refsource_HP
27298
third-party-advisory
x_refsource_SECUNIA
1018837
vdb-entry
x_refsource_SECTRACK
ADV-2007-3544
vdb-entry
x_refsource_VUPEN
20470
third-party-advisory
x_refsource_SECUNIA
USN-535-1
vendor-advisory
x_refsource_UBUNTU
20472
third-party-advisory
x_refsource_SECUNIA
20467
third-party-advisory
x_refsource_SECUNIA
ADV-2006-2160
vdb-entry
x_refsource_VUPEN
27383
third-party-advisory
x_refsource_SECUNIA
SUSE-SA:2007:057
vendor-advisory
x_refsource_SUSE
21532
third-party-advisory
x_refsource_SECUNIA
ADV-2008-0083
vdb-entry
x_refsource_VUPEN
27387
third-party-advisory
x_refsource_SECUNIA
ADV-2006-2164
vdb-entry
x_refsource_VUPEN
18308
vdb-entry
x_refsource_BID
27403
third-party-advisory
x_refsource_SECUNIA
ADV-2006-2162
vdb-entry
x_refsource_VUPEN
SSRT061181
vendor-advisory
x_refsource_HP
MDKSA-2007:202
vendor-advisory
x_refsource_MANDRIVA
27335
third-party-advisory
x_refsource_SECUNIA
FEDORA-2007-2664
vendor-advisory
x_refsource_FEDORA
MDKSA-2006:143
vendor-advisory
x_refsource_MANDRIVA
20442
third-party-advisory
x_refsource_SECUNIA
201516
vendor-advisory
x_refsource_SUNALERT
20071029 rPSA-2007-0225-2 firefox thunderbird
mailing-list
x_refsource_BUGTRAQ
USN-536-1
vendor-advisory
x_refsource_UBUNTU

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now