CVE-2006-1729

Severity
4.3MEDIUM
EPSS
1.8%
top 17.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 14
Latest updateMay 3

Description

Mozilla Firefox 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to read arbitrary files by (1) inserting the target filename into a text box, then turning that box into a file upload control, or (2) changing the type of the input control that is associated with an event handler.

CVSS vector

AV:N/AC:M/C:P/I:N/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

NVDmozilla/firefox1.01.0.8+1
NVDmozilla/seamonkey< 1.0.1
NVDmozilla/mozilla_suite< 1.7.13

Also affects: Ubuntu Linux 4.10, 5.04, 5.10

🔴Vulnerability Details

2
GHSA
GHSA-2gxf-f3cr-5m3p: Mozilla Firefox 12022-05-03
CVEList
CVE-2006-1729: Mozilla Firefox 12006-04-14

📋Vendor Advisories

5
Red Hat
security flaw2006-06-01
Ubuntu
Mozilla vulnerabilities2006-04-28
Ubuntu
Firefox vulnerabilities2006-04-20
Red Hat
security flaw2006-04-14
Debian
CVE-2006-1729: firefox - Mozilla Firefox 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before ...2006

💬Community

6
Bugzilla
CVE-2006-2782 security flaw2018-08-16
Bugzilla
CVE-2006-1729 security flaw2018-08-16
Bugzilla
CVE-2006-1729 File stealing by changing input type2006-04-13
Bugzilla
CVE-2006-1729 File stealing by changing input type2006-04-13
Bugzilla
CVE-2006-1729 File stealing by changing input type2006-04-13
CVE-2006-1729 (MEDIUM CVSS 4.3) | Mozilla Firefox 1.x before 1.5.0.2 | cvebase.io