CVE-2006-2782: Input Validation
Published Jun 2, 2006
·Updated
Firefox 1.5.0.2 does not fix all test cases associated with CVE-2006-1729, which allows remote attackers to read arbitrary files by inserting the target filename into a text box, then turning that box into a file upload control.
Affected Software
2 affected components
Mozilla Firefox<=1.5.0.3
Mozilla SeaMonkey<=1.0.1
Event History
Jun 2, 2006
CVE Published
07:02 PM
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-2782?
CVE-2006-2782 has a medium severity rating due to its ability to allow attackers to read arbitrary files.
2
How do I fix CVE-2006-2782?
To fix CVE-2006-2782, users should update their Firefox or SeaMonkey browsers to a version later than the affected ones.
3
Which versions of Firefox are affected by CVE-2006-2782?
CVE-2006-2782 affects Mozilla Firefox versions up to 1.5.0.3.
4
Which versions of SeaMonkey are impacted by CVE-2006-2782?
CVE-2006-2782 impacts SeaMonkey versions up to 1.0.1.
5
What type of vulnerability is CVE-2006-2782 classified as?
CVE-2006-2782 is classified as a file access vulnerability.