Lucene search

K
mozillaMozilla FoundationMFSA2007-32
HistoryOct 18, 2007 - 12:00 a.m.

File input focus stealing vulnerability — Mozilla

2007-10-1800:00:00
Mozilla Foundation
www.mozilla.org
17

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.063

Percentile

93.8%

A user on the Sla.ckers.org forums named hong reported that a file upload control could be filled programmatically by switching page focus to the label before a file upload form control for selected keyboard events. An attacker could use this trick to steal files from the users’ computer if the attacker knew the full pathnames to the desired fileis and could create a pretext that would convince the user to type long enough to produce all the necessary characters.

Affected configurations

Vulners
Node
mozillafirefoxRange<2.0.0.8
OR
mozillaseamonkeyRange<1.1.5

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.063

Percentile

93.8%