A weakness has been discovered in Firefox, which potentially can be exploited by malicious people to disclose sensitive information.
The weakness is caused due to a design error within the focus handling of form fields and can potentially be exploited by changing the focus from a "textarea" field to a "file upload" form field via the "OnKeyDown" event.
Successful exploitation allows an arbitrary file on the user's system to be uploaded to a malicious web site, but requires that the user is tricked into typing the file name into a "textarea" input form.
The weakness is confirmed in version 18.104.22.168. Other versions may also be affected.
Solution: Update to version 22.214.171.124.
Provided and/or discovered by: Hong
Original Advisory: Mozilla Foundation:
Do you have additional information related to this advisory?
Please provide information about patches, mitigating factors, new versions, exploits, faulty patches, links, and other relevant data by posting comments to this Advisory. You can also send this
information to email@example.com
Subject: Firefox "OnKeyDown" Event Focus Weakness
No posts yet
You must be logged in to post a comment.
Secunia Customer Login
Not a customer already?
Learn more about how our market leading Vulnerability Management solutions can help you manage risk and ensure compliance.