Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:18259
HistoryOct 23, 2007 - 12:00 a.m.

Mozilla Foundation Security Advisory 2007-32

2007-10-2300:00:00
vulners.com
22

Mozilla Foundation Security Advisory 2007-32

Title: File input focus stealing vulnerability
Impact: Moderate
Announced: October 18, 2007
Reporter: hong, Charles McAuley
Products: Firefox, SeaMonkey

Fixed in: Firefox 2.0.0.8
SeaMonkey 1.1.5
Description

A user on the Sla.ckers.org forums named hong reported that a file upload control could be filled programmatically by switching page focus to the label before a file upload form control for selected keyboard events. An attacker could use this trick to steal files from the users' computer if the attacker knew the full pathnames to the desired fileis and could create a pretext that would convince the user to type long enough to produce all the necessary characters.

This is a variant on a similar problem reported by Charles McAuley and independently rediscovered by Michal Zalewski that was fixed in Firefox 2.0.0.4.
References

* https://bugzilla.mozilla.org/show_bug.cgi?id=388784
* CVE-2007-3511
* https://bugzilla.mozilla.org/show_bug.cgi?id=370092
* CVE-2006-2894