Opera 6.0.1 allows remote attackers to upload arbitrary file contents when users press a key corresponding to the JavaScript (1) event.ctrlKey or (2) event.shiftKey onkeydown event contained in a webpage.
Link | Tags |
---|---|
http://online.securityfocus.com/archive/1/283866 | mailing list |
http://online.securityfocus.com/archive/1/284096 | mailing list |
http://www.securityfocus.com/bid/5290 | vdb entry exploit |