Windows BBS The Place for Microsoft Windows Support! Windows, Support, Help Site

Go Back   Windows BBS > Internet & Networking > Firefox, Thunderbird & SeaMonkey

Firefox, Thunderbird & SeaMonkey Post your questions about Mozilla based products (Firefox, Thunderbird & SeaMonkey) here.

Register your FREE account to unlock additional features at WindowsBBS.com
Register
Welcome to WindowsBBS.com
Microsoft Windows Support

Mission Statement

WindowsBBS is an online community dedicated to easily accessible technical support for those using Microsoft operating systems and other Windows software.

Our goal is to become the leading resource for computer users that require assistance with their day-to-day computer usage, including full support for networking PC's, virus & malware removal, system upgrades and general support questions.


Discussion Forums
Operating Systems
Windows 7 Windows 7
Windows Vista Windows Vista
Windows XP Windows XP
Windows Server System Windows Server System
Windows 2000 Windows 2000
Windows 95/98/Me/NT Windows 95/98/Me/NT
Internet & Networking
Networking
Internet Explorer
Microsoft Mail
Firefox, Thunderbird
      & SeaMonkey

General Internet
Security
General Security
Malware and Virus
     Removal

Other
Other Software
Hardware
Test Posts
Community
Introductions
General Discussions
Comments
      & Suggestions

News @ WindowsBBS

Forum Sponsor
 Image

Reply
 
LinkBack Thread Tools
Old 6th June 2006   #1
WindowsBBS Team Member
 
Ramona's Avatar
 
Profile:
Join Date: Dec 2001
Location: Missouri
Posts: 7,501
Computer Experience:
Experienced Learner
Ramona Reputation LevelRamona Reputation LevelRamona Reputation LevelRamona Reputation LevelRamona Reputation LevelRamona Reputation LevelRamona Reputation LevelRamona Reputation LevelRamona Reputation LevelRamona Reputation LevelRamona Reputation Level

My System

Firefox File Upload Form Keystroke Event Cancel Vulnerability

TITLE:
Firefox File Upload Form Keystroke Event Cancel Vulnerability
Quote:
SECUNIA ADVISORY ID:
SA20442

VERIFY ADVISORY:
http://secunia.com/advisories/20442/

CRITICAL:
Less critical

IMPACT:
Exposure of sensitive information

WHERE:
>From remote

SOFTWARE:
Mozilla Firefox 1.x
http://secunia.com/product/4227/

DESCRIPTION:
Charles McAuley has reported a vulnerability in Firefox, which can be
exploited by malicious people to trick users into disclosing sensitive
information.

The vulnerability is caused due to a design error where a script can
cancel certain keystroke events when entering text. This can be
exploited to trick a user into typing a filename in a file upload
input field by changing focus and cancel the "OnKeyPress" JavaScript
event on certain characters.

Successful exploitation allows an arbitrary file on the user's system
to be uploaded to a malicious web site, but requires that the user
types a text containing the characters of the filename.

The vulnerability has been confirmed in version 1.5.0.4. Other
versions may also be affected.

SOLUTION:
Disable JavaScript support.

Do not enter suspicious text when visiting untrusted web sites.

PROVIDED AND/OR DISCOVERED BY:
Charles McAuley

NOTE: A variant of this vulnerability was reported in a Mozilla
Bugzilla bug entry back in year 2000.

ORIGINAL ADVISORY:
Charles McAuley:
http://lists.grok.org.uk/pipermail/f...ne/046610.html

Ramona is offline   Reply With Quote
Didn't find the information you thought to find?
Check out these Similar Threads
Reply

Thread Tools


Similar Threads
Thread Thread Starter Forum Replies Last Post
Need to reinstall IE [HijackThis log] msbooch Malware and Virus Removal 30 27th May 2005 02:25
Sooo many popups and Adware/spybot isn't doing its job!!! Up your ringer Malware and Virus Removal 25 10th December 2004 18:44
Question on Trogan viruses. jbh General Security 6 31st August 2004 04:50
Event viewer-Application, what is this? martinr121 Windows XP 27 11th April 2004 03:59
Win XP and SFC jabiru Windows XP 18 1st December 2003 22:07


All times are GMT +1. The time now is 03:30.






Advertisements do not imply our endorsement of the product or service advertised.
Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.3.2
Copyright © 2002 - 2009 WindowsBBS.com. All rights reserved.
Terms of Use, Legal Information & Privacy Policy
[]