| Mozilla Firefox 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla
Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote
attackers to read arbitrary files by (1) inserting the target filename
into a text box, then turning that box into a file upload control, or
(2) changing the type of the input control that is associated with an
event handler.
|