Total vulnerabilities in the database
Mozilla before 1.7 allows remote web servers to read arbitrary files via Javascript that sets the value of an <input type="file"> tag.
CVSS v2:
No CWE or OWASP classifications available.