CVE Reference: CVE-2006-2894

NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2006-2894

Description:
Mozilla Firefox 1.5.0.4, 2.0.x before 2.0.0.8, Mozilla Suite 1.7.13, Mozilla SeaMonkey 1.0.2 and other versions before 1.1.5, and Netscape 8.1 and earlier allow user-assisted remote attackers to read arbitrary files by tricking a user into typing the characters of the target filename in a text box and using the OnKeyDown, OnKeyPress, and OnKeyUp Javascript keystroke events to change the focus and cause those characters to be inserted into a file upload input control, which can then upload the file when the user submits the form.

CVE Status:
Candidate

References:

UBUNTU
  http://www.ubuntu.com/usn/usn-536-1
  http://www.ubuntulinux.org/support/documentation/usn/usn-535-1

SUSE
  http://www.novell.com/linux/security/advisories/2007_57_mozilla.html

SUNALERT
  http://sunsolve.sun.com/search/document.do?assetkey=1-66-201516-1

ST
  1018837

SREASON
  http://securityreason.com/securityalert/1059

SAID
  Secunia Advisory: SA27383
  Secunia Advisory: SA27335
  Secunia Advisory: SA21532
  Secunia Advisory: SA20470
  Secunia Advisory: SA20472
  Secunia Advisory: SA20467
  Secunia Advisory: SA20442
  Secunia Advisory: SA27403
  Secunia Advisory: SA27387
  Secunia Advisory: SA27298
  Secunia Advisory: SA27414

MISC
  http://www.gnucitizen.org/blog/browser-focus-rip
  http://www.thanhngan.org/fflinuxversion.html
  http://lcamtuf.coredump.cx/focusbug/

MANDRIVA
  http://www.mandriva.com/security/advisories?name=MDKSA-2006:145
  http://www.mandriva.com/en/security/advisories?name=MDKSA-2007:202
  http://www.mandriva.com/security/advisories?name=MDKSA-2006:143

HP
  http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742

FULLDISC
  http://lists.grok.org.uk/pipermail/full-disclosure/2006-June/046610.html
  http://lists.virus.org/full-disclosure-0702/msg00225.html

FEDORA

CONFIRM
  http://support.novell.com/techcenter/psdb/60eb95b75c76f9fbfcc9a89f99cd8f79.html
  http://www.mozilla.org/security/announce/2007/mfsa2007-32.html

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/482932/100/200/threaded
  http://www.securityfocus.com/archive/1/archive/1/482876/100/200/threaded
  http://www.securityfocus.com/archive/1/archive/1/482925/100/0/threaded
  http://archives.neohapsis.com/archives/bugtraq/2007-02/0187.html
  http://archives.neohapsis.com/archives/bugtraq/2007-02/0166.html

BID
  18308


Return to the previous page.