You are here: Known Vulnerabilities in Mozilla Products (Firefox 188.8.131.52) > MFSA 2008-27
Mozilla Foundation Security Advisory 2008-27
Title: Arbitrary file upload via originalTarget and DOM Range
Announced: July 1, 2008
Reporter: Opera Software
Products: Firefox, SeaMonkey
Fixed in: Firefox 184.108.40.206
Opera Software reported a vulnerability which allows malicious content to force the browser into uploading local files to the remote server. This could be used by an attacker to steal files from known locations on a victim's computer.
Firefox 3 is not vulnerable to this attack due to the changed design of the file upload form element.