File Upload Vulnerability in Mozilla Firefox and Related Products
CVE-2006-2894
Key Information:
- Vendor
Mozilla
- Vendor
- CVE Published:
- 7 June 2006
What is CVE-2006-2894?
A vulnerability in multiple versions of Mozilla Firefox and related products allows user-assisted remote attackers to read arbitrary files. By deceiving a user into inputting the characters of a target filename in a text box, malicious actors exploit JavaScript keystroke events such as OnKeyDown, OnKeyPress, and OnKeyUp to manipulate focus. This may lead to those characters being inserted into a file upload control. Consequently, a user inadvertently uploads sensitive files upon form submission, thereby compromising user data security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
EPSS Score
6% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved