CENTER.HU groups
CENTER.HU address

User:

Guest

www.center.hu / Archive / Security news / june, 2006 / A vulnerability in multiple browsers grants access to remote files 

A vulnerability in multiple browsers grants access to remote

A vulnerability in multiple browsers grants access to remote

Madrid, June 7 2006 - FrSIRT has reported a vulnerability in the most widely used browsers, which could be exploited by remote attackers to gain unauthorized access to arbitrary files.

The flaw stems from a design error that allows keystroke events to be cancelled through JavaScript code, which could be exploited by remote attackers to make users upload arbitrary files inadvertently from a vulnerable system to a malicious host. To do this, it is necessary to trick target users into visiting a maliciously crafted web page and carry out certain actions (like typing a text in a text field), which will cause an arbitrary file to be uploaded automatically.

Rather unusually, this flaw does not affect a single browser, but several: Mozilla Firefox 1.5.0.4 and prior versions, Mozilla SeaMonkey 1.0.2 and prior versions, Netscape 8.1 and prior versions, Mozilla Suite 1.7.13 and prior versions, and Internet Explorer 6 and 5.01. Also, a demo exploit has been published as proof of concept for this flaw.


Oxygen3 24h-365d
 by Panda Software

Back




Copyright © CENTER.HU Ltd, 2000-2010. All rights reserved

sitemap | privacy policy |

copyrights | new pages |

terms of purchase | contact us


PARTNERS: Computerworld.hu | GameStar.hu | PCWorld.hu | SG.hu | PC Guru | Hitel