CVE-2006-2894

Mozilla Firefox <2.0.0.8 - Info Disclosure

Title source: llm

Description

Mozilla Firefox 1.5.0.4, 2.0.x before 2.0.0.8, Mozilla Suite 1.7.13, Mozilla SeaMonkey 1.0.2 and other versions before 1.1.5, and Netscape 8.1 and earlier allow user-assisted remote attackers to read arbitrary files by tricking a user into typing the characters of the target filename in a text box and using the OnKeyDown, OnKeyPress, and OnKeyUp Javascript keystroke events to change the focus and cause those characters to be inserted into a file upload input control, which can then upload the file when the user submits the form.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Jesse Ruderman · htmlremotewindows
https://www.exploit-db.com/exploits/27986
exploitdb WORKING POC VERIFIED
by Jesse Ruderman · htmlremotelinux
https://www.exploit-db.com/exploits/27987

Scores

EPSS 0.0691
EPSS Percentile 91.4%

Details

CWE
CWE-20
Status published
Products (6)
mozilla/firefox 1.5.0.4
mozilla/firefox < 2.0.0.8
mozilla/mozilla_suite 1.7.13
mozilla/seamonkey 1.0.2
mozilla/seamonkey < 1.1.4
netscape/navigator < 8.1
Published Jun 07, 2006
Tracked Since Feb 18, 2026