|
Brought to you by:
Suppliers of:
|
|
|
| |
Mozilla Firefox - The award-winning, free Web browser.
Using a specially crafted HTML form, it is possible to crash Firefox. |
| |
Credit:
The information has been provided by reyw.
|
| |
Vulnerable Systems:
* Firefox version 1.5.0.4 and prior.
Send any file by the form with ENCTYPE="multipart/form-data" and method="POST" when file upload successful try refresh page (F5 or refresh button).
* Upload file by form
* Refresh page
* Firefox crash with segfault
Example html:
<form action="" ENCTYPE="multipart/form-data" method="POST">
file name:<input type="file" name="filee">
<input type="submit">
</form>
|
| Subject:
|
Not Linux |
Date: |
28 Aug. 2006 |
| From: |
Giz |
| Does not seem to affect Linux systems but can cause windoze problems. I.e. this is a windows problem for Firefox? |
|
| Subject:
|
Not for me! |
Date: |
3 Sep. 2006 |
| From: |
mfaras |
Tested in WinXP sp2, FF 1.5.0.6
Y pasted the code in an empty file, called "e;f.html"e;, put it in my local apache document root, acessed it, uploaded a small file, and then refreshed. The warning pops out about having to post again, clicked ok, and everything was allright. I had several other tabs open. |
|
| Subject:
|
Not for me! |
Date: |
3 Sep. 2006 |
| From: |
mfaras |
Tested in WinXP sp2, FF 1.5.0.6
Y pasted the code in an empty file, called "e;f.html"e;, put it in my local apache document root, accessed it, uploaded a small file, and then refreshed. The warning pops out about having to post again, clicked ok, and everything was alright. I had several other tabs open. |
|
| Subject:
|
@mfaras |
Date: |
4 Sep. 2006 |
| From: |
junior |
Quoting:
Vulnerable Systems:
* Firefox version 1.5.0.4 and prior. |
|
|
|
|
|
|