CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:M/Au:N/C:P/I:N/A:N
EPSS
Percentile
92.6%
Mozilla Firefox 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite
before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to read
arbitrary files by (1) inserting the target filename into a text box, then
turning that box into a file upload control, or (2) changing the type of
the input control that is associated with an event handler.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
ubuntu | 6.06 | noarch | firefox | < 1.5.dfsg+1.5.0.13~prepatch070731-0ubuntu1 | UNKNOWN |
ubuntu | 6.10 | noarch | firefox | < 2.0.0.6+0dfsg-0ubuntu0.6.10 | UNKNOWN |
ubuntu | 7.04 | noarch | firefox | < 2.0.0.6+1-0ubuntu1 | UNKNOWN |
ubuntu | 6.10 | noarch | xulrunner | < 1.8.0.5-4.2 | UNKNOWN |
ubuntu | 7.04 | noarch | xulrunner | < 1.8.0.5-4.2 | UNKNOWN |