CVE-2009-0355
CVE-2009-0355
components/sessionstore/src/nsSessionStore.js in Mozilla Firefox before 3.0.6 does not block changes of INPUT elements to type="file" during tab restoration, which allows user-assisted remote attackers to read arbitrary files on a client machine via a crafted INPUT element.
Productos afectados
n/a · n/a¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00001.htmlhttp://rhn.redhat.com/errata/RHSA-2009-0256.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=466937http://secunia.com/advisories/33799http://secunia.com/advisories/33808http://secunia.com/advisories/33809http://secunia.com/advisories/33816http://secunia.com/advisories/33831http://secunia.com/advisories/33841http://secunia.com/advisories/33846http://secunia.com/advisories/33869http://secunia.com/advisories/34324