Mozilla Firefox 1.5.0.4, 2.0.x before 2.0.0.8, Mozilla Suite 1.7.13, Mozilla SeaMonkey 1.0.2 and other versions before 1.1.5, and Netscape 8.1 and earlier allow user-assisted remote attackers to read arbitrary files by tricking a user into typing the characters of the target filename in a text box and using the OnKeyDown, OnKeyPress, and OnKeyUp Javascript keystroke events to change the focus and cause those characters to be inserted into a file upload input control, which can then upload the file when the user submits the form.

Project Subscriptions

Vendors Products
Mozilla Subscribe
Firefox Subscribe
Mozilla Suite Subscribe
Seamonkey Subscribe
Netscape Subscribe
Navigator Subscribe
Advisories
Source ID Title
Debian DSA Debian DSA DSA-1392-1 New xulrunner packages fix several vulnerabilities
Debian DSA Debian DSA DSA-1396-1 New iceweasel packages fix several vulnerabilities
Debian DSA Debian DSA DSA-1401-1 New iceape packages fix several vulnerabilities
EUVD EUVD EUVD-2006-2891 Mozilla Firefox 1.5.0.4, 2.0.x before 2.0.0.8, Mozilla Suite 1.7.13, Mozilla SeaMonkey 1.0.2 and other versions before 1.1.5, and Netscape 8.1 and earlier allow user-assisted remote attackers to read arbitrary files by tricking a user into typing the characters of the target filename in a text box and using the OnKeyDown, OnKeyPress, and OnKeyUp Javascript keystroke events to change the focus and cause those characters to be inserted into a file upload input control, which can then upload the file when the user submits the form.
Ubuntu USN Ubuntu USN USN-535-1 Firefox vulnerabilities
Ubuntu USN Ubuntu USN USN-536-1 Thunderbird vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
http://archives.neohapsis.com/archives/bugtraq/2007-02/0166.html cve-icon cve-icon
http://archives.neohapsis.com/archives/bugtraq/2007-02/0187.html cve-icon cve-icon
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742 cve-icon cve-icon
http://lcamtuf.coredump.cx/focusbug/ cve-icon cve-icon
http://lists.grok.org.uk/pipermail/full-disclosure/2006-June/046610.html cve-icon cve-icon
http://lists.virus.org/full-disclosure-0702/msg00225.html cve-icon cve-icon
http://secunia.com/advisories/20442 cve-icon cve-icon
http://secunia.com/advisories/20467 cve-icon cve-icon
http://secunia.com/advisories/20470 cve-icon cve-icon
http://secunia.com/advisories/20472 cve-icon cve-icon
http://secunia.com/advisories/21532 cve-icon cve-icon
http://secunia.com/advisories/27298 cve-icon cve-icon
http://secunia.com/advisories/27335 cve-icon cve-icon
http://secunia.com/advisories/27383 cve-icon cve-icon
http://secunia.com/advisories/27387 cve-icon cve-icon
http://secunia.com/advisories/27403 cve-icon cve-icon
http://secunia.com/advisories/27414 cve-icon cve-icon
http://securityreason.com/securityalert/1059 cve-icon cve-icon
http://securitytracker.com/id?1018837 cve-icon cve-icon
http://sunsolve.sun.com/search/document.do?assetkey=1-66-201516-1 cve-icon cve-icon
http://support.novell.com/techcenter/psdb/60eb95b75c76f9fbfcc9a89f99cd8f79.html cve-icon cve-icon
http://www.gnucitizen.org/blog/browser-focus-rip cve-icon cve-icon
http://www.mandriva.com/en/security/advisories?name=MDKSA-2007:202 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDKSA-2006:143 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDKSA-2006:145 cve-icon cve-icon
http://www.mozilla.org/security/announce/2007/mfsa2007-32.html cve-icon cve-icon
http://www.novell.com/linux/security/advisories/2007_57_mozilla.html cve-icon cve-icon
http://www.securityfocus.com/archive/1/482876/100/200/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/482925/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/482932/100/200/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/18308 cve-icon cve-icon
http://www.thanhngan.org/fflinuxversion.html cve-icon cve-icon
http://www.ubuntu.com/usn/usn-536-1 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/2160 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/2162 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/2163 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/2164 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/3544 cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/0083 cve-icon cve-icon
https://bugzilla.mozilla.org/show_bug.cgi?id=290478 cve-icon cve-icon
https://bugzilla.mozilla.org/show_bug.cgi?id=370092 cve-icon cve-icon
https://bugzilla.mozilla.org/show_bug.cgi?id=56236 cve-icon cve-icon
https://issues.rpath.com/browse/RPL-1858 cve-icon cve-icon
https://usn.ubuntu.com/535-1/ cve-icon cve-icon
https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00355.html cve-icon cve-icon
History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-07T18:06:27.190Z

Reserved: 2006-06-07T00:00:00

Link: CVE-2006-2894

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2006-06-07T10:02:00.000

Modified: 2025-04-03T01:03:51.193

Link: CVE-2006-2894

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses