The focus handling for the onkeydown event in Mozilla Firefox 1.5.0.12, 2.0.0.4 and other versions before 2.0.0.8, and SeaMonkey before 1.1.5 allows remote attackers to change field focus and copy keystrokes via the "for" attribute in a label, which bypasses the focus prevention, as demonstrated by changing focus from a textarea to a file upload field.
References
Link Providers
http://archives.neohapsis.com/archives/fulldisclosure/2007-06/0646.html cve-icon cve-icon
http://archives.neohapsis.com/archives/fulldisclosure/2007-06/0658.html cve-icon cve-icon
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742 cve-icon cve-icon
http://osvdb.org/37994 cve-icon cve-icon
http://secunia.com/advisories/25904 cve-icon cve-icon
http://secunia.com/advisories/27276 cve-icon cve-icon
http://secunia.com/advisories/27298 cve-icon cve-icon
http://secunia.com/advisories/27325 cve-icon cve-icon
http://secunia.com/advisories/27327 cve-icon cve-icon
http://secunia.com/advisories/27335 cve-icon cve-icon
http://secunia.com/advisories/27336 cve-icon cve-icon
http://secunia.com/advisories/27356 cve-icon cve-icon
http://secunia.com/advisories/27383 cve-icon cve-icon
http://secunia.com/advisories/27387 cve-icon cve-icon
http://secunia.com/advisories/27403 cve-icon cve-icon
http://secunia.com/advisories/27414 cve-icon cve-icon
http://secunia.com/advisories/27425 cve-icon cve-icon
http://secunia.com/advisories/27480 cve-icon cve-icon
http://secunia.com/advisories/27680 cve-icon cve-icon
http://securitytracker.com/id?1018837 cve-icon cve-icon
http://sla.ckers.org/forum/read.php?3%2C13142 cve-icon cve-icon
http://sunsolve.sun.com/search/document.do?assetkey=1-66-201516-1 cve-icon cve-icon
http://support.novell.com/techcenter/psdb/60eb95b75c76f9fbfcc9a89f99cd8f79.html cve-icon cve-icon
http://www.debian.org/security/2007/dsa-1392 cve-icon cve-icon
http://www.debian.org/security/2007/dsa-1396 cve-icon cve-icon
http://www.debian.org/security/2007/dsa-1401 cve-icon cve-icon
http://www.mandriva.com/en/security/advisories?name=MDKSA-2007:202 cve-icon cve-icon
http://www.mozilla.org/security/announce/2007/mfsa2007-32.html cve-icon cve-icon
http://www.novell.com/linux/security/advisories/2007_57_mozilla.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2007-0979.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2007-0980.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2007-0981.html cve-icon cve-icon
http://www.securityfocus.com/archive/1/482876/100/200/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/482925/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/482932/100/200/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/24725 cve-icon cve-icon
http://www.ubuntu.com/usn/usn-536-1 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/3544 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/3587 cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/0083 cve-icon cve-icon
http://yathong.googlepages.com/FirefoxFocusBug.html cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/35299 cve-icon cve-icon
https://issues.rpath.com/browse/RPL-1858 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2007-3511 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9763 cve-icon cve-icon
https://usn.ubuntu.com/535-1/ cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2007-3511 cve-icon
https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00498.html cve-icon cve-icon
https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00285.html cve-icon cve-icon
https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00355.html cve-icon cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2007-07-03T10:00:00

Updated: 2024-08-07T14:21:36.262Z

Reserved: 2007-07-02T00:00:00

Link: CVE-2007-3511

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2007-07-03T10:30:00.000

Modified: 2023-11-07T02:00:51.193

Link: CVE-2007-3511

cve-icon Redhat

Severity : Moderate

Publid Date: 2007-06-30T00:00:00Z

Links: CVE-2007-3511 - Bugzilla