You are here: Known Vulnerabilities in Mozilla Products (Firefox 220.127.116.11) > MFSA 2008-02
Mozilla Foundation Security Advisory 2008-02
Title: Multiple file input focus stealing vulnerabilities
Announced: February 7, 2008
Reporter: hong, Gregory Fleischer
Products: Firefox, SeaMonkey
Fixed in: Firefox 18.104.22.168
Security researchers hong and Gregory
Fleischer each reported a variant on earlier reported bugs
regarding focus shifting in file input controls. Their variants
used file input controls nested inside
to take advantage of automatic focus shifting into the file input field
noted on the Hacker WebZine. As with the earlier reported issues
this issue could be used to force a user to upload arbitrary files
assuming the attacker knows the full path and name of the file.
These bugs are variations on earlier problems reported by Charles McAuley and Michal Zalewski which were fixed in Firefox 22.214.171.124, as well as an issue reported by hong which was fixed in Firefox 126.96.36.199.
Gregory Fleischer also submitted several other variations of the same problem.
- Focus shifting bugs
(proofs-of-concept details embargoed)