File Upload Vulnerability in Mozilla Firefox and Related Products
CVE-2006-2894

Currently unrated

Key Information:

Vendor
Mozilla
Vendor
CVE Published:
7 June 2006

Summary

A vulnerability in multiple versions of Mozilla Firefox and related products allows user-assisted remote attackers to read arbitrary files. By deceiving a user into inputting the characters of a target filename in a text box, malicious actors exploit JavaScript keystroke events such as OnKeyDown, OnKeyPress, and OnKeyUp to manipulate focus. This may lead to those characters being inserted into a file upload control. Consequently, a user inadvertently uploads sensitive files upon form submission, thereby compromising user data security.

References

EPSS Score

6% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2006-2894 : File Upload Vulnerability in Mozilla Firefox and Related Products | SecurityVulnerability.io