You are here: Known Vulnerabilities in Mozilla Products (Firefox 220.127.116.11) > MFSA 2006-41
Mozilla Foundation Security Advisory 2006-41
Title: File stealing by changing input type (variant)
Date: June 1, 2006
Reporter: Chuck McAuley
Products: Firefox, SeaMonkey
Fixed in: Firefox 18.104.22.168
Chuck McAuley provided Proof-of-Concept code that demonstrates that MFSA 2006-23 was not fixed for all cases. In Firefox 22.214.171.124 it is still possible to pre-fill a text input control with the path to a file at a known location and then change the type of the input control to a file upload control without having the value reset as intended.