Mozilla Firefox 1.5.0.4, 2.0.x before 2.0.0.8, Mozilla Suite 1.7.13, Mozilla SeaMonkey 1.0.2 and other versions before 1.1.5, and Netscape 8.1 and earlier allow user-assisted remote attackers to read arbitrary files by tricking a user into typing the characters of the target filename in a text box and using the OnKeyDown, OnKeyPress, and OnKeyUp Javascript keystroke events to change the focus and cause those characters to be inserted into a file upload input control, which can then upload the file when the user submits the form.
CVSS Details
- CVSS 3.1 Base Score: 6.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Mfsa2007 32 | — | Upgrade to Mozilla Firefox version 2.0.0.8 | Jun 14, 2012 | Jun 7, 2006 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 1.1.5 | Feb 3, 2012 | Jun 7, 2006 |
| Suse | — | Upgrade seamonkey-ircUpgrade mozilla-ircUpgrade mozilla-deatUpgrade mozilla-huUpgrade seamonkey-venkmanUpgrade seamonkey-spellcheckerUpgrade mozilla-venkmanUpgrade mozilla-dom-inspectorUpgrade mozillaUpgrade seamonkey-mailUpgrade mozilla-calendarUpgrade mozilla-mailUpgrade mozilla-csUpgrade seamonkeyUpgrade mozilla-develUpgrade seamonkey-dom-inspectorUpgrade MozillaFirefoxUpgrade MozillaFirefox-translationsUpgrade suse-release | Feb 17, 2015 | Jun 7, 2006 |
| Ubuntu | — | Upgrade firefoxUpgrade mozilla-thunderbird | Nov 8, 2024 | Jun 7, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub