4.3
CVSSv2

CVE-2013-1671

Published: 16/05/2013 Updated: 19/09/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

Mozilla Firefox prior to 21.0 does not properly implement the INPUT element, which allows remote malicious users to obtain the full pathname via a crafted web site.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox

mozilla firefox 19.0

mozilla firefox 19.0.1

mozilla firefox 19.0.2

mozilla firefox 20.0

Vendor Advisories

Firefox could be made to crash or run programs as your login if it opened a malicious website ...
Mozilla Foundation Security Advisory 2013-43 File input control has access to full path Announced May 14, 2013 Reporter moz_bug_r_a4 Impact Moderate Products Firefox Fixed in Firef ...
Mozilla Firefox before 210 does not properly implement the INPUT element, which allows remote attackers to obtain the full pathname via a crafted web site ...