File Upload Vulnerability in Mozilla Firefox and Related Products
CVE-2006-2894
Currently unrated
Key Information:
- Vendor
- Mozilla
- Vendor
- CVE Published:
- 7 June 2006
Summary
A vulnerability in multiple versions of Mozilla Firefox and related products allows user-assisted remote attackers to read arbitrary files. By deceiving a user into inputting the characters of a target filename in a text box, malicious actors exploit JavaScript keystroke events such as OnKeyDown, OnKeyPress, and OnKeyUp to manipulate focus. This may lead to those characters being inserted into a file upload control. Consequently, a user inadvertently uploads sensitive files upon form submission, thereby compromising user data security.
References
EPSS Score
6% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved