Vulnerability Name: | CVE-2004-0759 (CCN-16870) | ||||||||||||||||
Assigned: | 2004-07-22 | ||||||||||||||||
Published: | 2004-07-22 | ||||||||||||||||
Updated: | 2017-10-11 | ||||||||||||||||
Summary: | Mozilla before 1.7 allows remote web servers to read arbitrary files via Javascript that sets the value of an <input type="file"> tag. | ||||||||||||||||
CVSS v3 Severity: | 6.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
| ||||||||||||||||
CVSS v2 Severity: | 6.4 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N)
| ||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||
References: | Source: SCO Type: UNKNOWN SCOSA-2005.49 Source: CCN Type: Mozilla Bugzilla Bug 241924 Mozilla can upload files without user confirmation Source: CONFIRM Type: Patch, Vendor Advisory Source: MITRE Type: CNA CVE-2004-0759 Source: CCN Type: Conectiva Linux Security Announcement CLSA-2004:877 New upstream for mozilla Source: FEDORA Type: UNKNOWN FLSA:2089 Source: CCN Type: RHSA-2004-421 mozilla security update Source: CCN Type: Slackware Security Advisories Tue, 10 Aug 2004 14:17:12 -0700 (PDT) [slackware-security] Mozilla (SSA:2004-223-01) Source: CCN Type: CIAC Information Bulletin O-195 Mozilla Updated Security Packages Source: CCN Type: Mozilla Web site Fixed in Mozilla 1.7/Firefox 0.9/Thunderbird 0.7 Source: CONFIRM Type: UNKNOWN Source: SUSE Type: UNKNOWN SUSE-SA:2004:036 Source: REDHAT Type: UNKNOWN RHSA-2004:421 Source: CCN Type: BID-10874 Mozilla Browser Input Type HTML Tag Unauthorized Access Vulnerability Source: BID Type: UNKNOWN 15495 Source: CCN Type: BID-15495 SCO OpenServer Release 5.0.7 Maintenance Pack 4 Released - Multiple Vulnerabilities Fixed Source: XF Type: UNKNOWN mozilla-warning-file-upload(16870) Source: XF Type: UNKNOWN mozilla-warning-file-upload(16870) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:11153 Source: SUSE Type: SUSE-SA:2004:030 apache2: remote DoS condition Source: SUSE Type: SUSE-SA:2004:031 cups: remote code execution Source: SUSE Type: SUSE-SA:2004:032 apache2: remote denial-of-service Source: SUSE Type: SUSE-SA:2004:033 gtk2 gdk-pixbuf: remote code execution Source: SUSE Type: SUSE-SA:2004:034 XFree86-libs xshared: remote command execution Source: SUSE Type: SUSE-SA:2004:035 samba: remote file disclosure Source: SUSE Type: SUSE-SA:2004:036 mozilla: various vulnerabilities | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration CCN 1: ![]() | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||