CVE-2006-2894

Description

Mozilla Firefox 1.5.0.4, 2.0.x before 2.0.0.8, Mozilla Suite 1.7.13, Mozilla SeaMonkey 1.0.2 and other versions before 1.1.5, and Netscape 8.1 and earlier allow user-assisted remote attackers to read arbitrary files by tricking a user into typing the characters of the target filename in a text box and using the OnKeyDown, OnKeyPress, and OnKeyUp Javascript keystroke events to change the focus and cause those characters to be inserted into a file upload input control, which can then upload the file when the user submits the form.

Risk Information

Base Score
6.5
MODERATE
Vector
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
6.905

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities affected in Mozilla Firefox (x64) 2.0.0.8Windows
Multiple vulnerabilities affected in Mozilla_Firefox 2.0.0.8Windows
Multiple vulnerabilities affected in SeaMonkey 1.1.4Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.5.0.4Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 2.0.0.8Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 1.5.0.4Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 2.0.0.8Windows
Multiple vulnerabilities are fixed in Mozilla Firefox For Mac 2.0.0.8Mac

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-343016Mozilla Firefox (x64) (132.0.2)
PATCH-343015Mozilla Firefox (132.0.2)
PATCH-341197SeaMonkey (2.53.19)
PATCH-613630Mozilla Firefox For Mac (147.0.4)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234