cbcvebase.
CVE-2013-1671
published 2013-05-16

CVE-2013-1671: Mozilla Firefox before 21.0 does not properly implement the INPUT element, which allows remote attackers to obtain the full pathname via a crafted web site.

PriorityP416medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
1.04%
60.7th percentile
Mozilla Firefox before 21.0 does not properly implement the INPUT element, which allows remote attackers to obtain the full pathname via a crafted web site.

Affected

5 ranges
VendorProductVersion rangeFixed in
mozillafirefox<= 20.0.1
mozillafirefox
mozillafirefox
mozillafirefox
mozillafirefox

CVSS provenance

nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_ubuntu10.0CRITICAL
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.