CVE-2006-1729
Summary
| CVE | CVE-2006-1729 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-04-14 10:02:00 UTC |
| Updated | 2018-10-18 16:34:00 UTC |
| Description | Mozilla Firefox 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to read arbitrary files by (1) inserting the target filename into a text box, then turning that box into a file upload control, or (2) changing the type of the input control that is associated with an event handler. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Canonical | Ubuntu Linux | 4.10 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 5.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 5.10 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 4.10 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 5.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 5.10 | All | All | All |
| Application | Mozilla | Firefox | All | All | All | All |
| Application | Mozilla | Firefox | All | All | All | All |
| Application | Mozilla | Mozilla Suite | All | All | All | All |
| Application | Mozilla | Mozilla Suite | All | All | All | All |
| Application | Mozilla | Seamonkey | All | All | All | All |
| Application | Mozilla | Seamonkey | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Mandriva update for firefox - Advisories - Secunia | SECUNIA | secunia.com | Third Party Advisory |
| [SECURITY] Fedora Core 5 Update: firefox-1.5.0.2-1.1.fc5 | FEDORA | www.redhat.com | Third Party Advisory |
| SGI Advanced Linux Environment 3 Multiple Updates - Advisories - Secunia | SECUNIA | secunia.com | Third Party Advisory |
| Webmail - OVH | VUPEN | www.vupen.com | Permissions Required, Third Party Advisory |
| Gentoo update for mozilla-firefox / mozilla-firefox-bin - Advisories - Secunia | SECUNIA | secunia.com | Third Party Advisory |
| Mozilla SeaMonkey Multiple Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | Third Party Advisory |
| USN-275-1: Mozilla vulnerabilities | Ubuntu security notices | UBUNTU | usn.ubuntu.com | Third Party Advisory |
| Gentoo Linux Documentation -- Mozilla Suite: Multiple vulnerabilities | GENTOO | www.gentoo.org | Third Party Advisory |
| Debian -- Security Information -- DSA-1051-1 mozilla-thunderbird | DEBIAN | www.debian.org | Third Party Advisory |
| rhn.redhat.com | Red Hat Support | REDHAT | www.redhat.com | Third Party Advisory |
| SecurityFocus | HP | www.securityfocus.com | |
| Security Announcement | SUSE | www.novell.com | Broken Link, Third Party Advisory |
| Mozilla Suite, Firefox, SeaMonkey, and Thunderbird Multiple Remote Vulnerabilities | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Ubuntu update for mozilla - Advisories - Secunia | SECUNIA | secunia.com | Third Party Advisory |
| Debian -- Security Information -- DSA-1044-1 mozilla-firefox | DEBIAN | www.debian.org | Third Party Advisory |
| HP-UX update for firefox - Advisories - Secunia | SECUNIA | secunia.com | Third Party Advisory |
| 20060404-01-U | SGI | patches.sgi.com | Broken Link |
| [SECURITY] Fedora Core 4 Update: firefox-1.0.8-1.1.fc4 | FEDORA | www.redhat.com | Third Party Advisory |
| Debian -- Security Information -- DSA-1046-1 mozilla | DEBIAN | www.debian.org | Third Party Advisory |
| Red Hat update for mozilla - Advisories - Secunia | SECUNIA | secunia.com | Third Party Advisory |
| Repository / Oval Repository | OVAL | oval.cisecurity.org | Third Party Advisory |
| Secunia - Advisories - Red Hat update for firefox | SECUNIA | secunia.com | Third Party Advisory |
| 228526 | SUNALERT | sunsolve.sun.com | Broken Link |
| USN-271-1: Firefox vulnerabilities | Ubuntu security notices | UBUNTU | usn.ubuntu.com | Third Party Advisory |
| SecurityFocus | FEDORA | www.securityfocus.com | |
| Repository / Oval Repository | OVAL | oval.cisecurity.org | Third Party Advisory |
| #102550: Multiple Security Vulnerabilites in Mozilla 1.4 and 1.7 for Solaris and for Sun JDS for Linux | SUNALERT | sunsolve.sun.com | Broken Link |
| SecurityFocus | FEDORA | www.securityfocus.com | |
| File stealing by changing input type — Mozilla | CONFIRM | www.mozilla.org | Vendor Advisory |
| Fedora update for firefox - Advisories - Secunia | SECUNIA | secunia.com | Third Party Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | Permissions Required, Third Party Advisory |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | Third Party Advisory, VDB Entry |
| Firefox Multiple Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | Third Party Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | Permissions Required, Third Party Advisory |
| Ubuntu update for firefox - Advisories - Secunia | SECUNIA | secunia.com | Third Party Advisory |
| Gentoo update for mozilla - Advisories - Secunia | SECUNIA | secunia.com | Third Party Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | Permissions Required, Third Party Advisory |
| SUSE update for mozilla/firefox - Advisories - Secunia | SECUNIA | secunia.com | Third Party Advisory |
| Debian update for mozilla - Advisories - Secunia | SECUNIA | secunia.com | Third Party Advisory |
| Debian update for mozilla-thunderbird - Advisories - Secunia | SECUNIA | secunia.com | Third Party Advisory |
| Advisories - Mandriva Linux | MANDRIVA | www.mandriva.com | Third Party Advisory |
| UnixWare update for mozilla - Advisories - Secunia | SECUNIA | secunia.com | Third Party Advisory |
| Advisories - Mandriva Linux | MANDRIVA | www.mandriva.com | Third Party Advisory |
| Gentoo Linux Documentation -- Mozilla Firefox: Multiple vulnerabilities | GENTOO | www.gentoo.org | Third Party Advisory |
| Debian update for mozilla-firefox - Advisories - Secunia | SECUNIA | secunia.com | Third Party Advisory |
| SuSE Security announcements: [suse-security-announce] SUSE Security Announcement: Mozilla Firefox, Mozilla Suite various problems (SUSE-SA:2006:021) | SUSE | lists.suse.com | Broken Link |
| SCOSA-2006.26 | SCO | ftp.sco.com | Broken Link |
| Sun Solaris update for mozilla - Advisories - Secunia | SECUNIA | secunia.com | Third Party Advisory |
| rhn.redhat.com | Red Hat Support | REDHAT | www.redhat.com | Third Party Advisory |
| ASA-2006-205 (SUN 102502, 102513, 102514, 102519, 102550, 102556, 102557, 102582, 102588, 102589, 102593) | CONFIRM | support.avaya.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.