Heap
08-07-08, 21:39
Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 allow remote attackers to force the upload of arbitrary local files from a client computer via vectors involving originalTarget and DOM Range.
More... (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2805)
More... (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2805)