petea / sage

A feed reader for Firefox.
http://sagerss.com
27 stars 8 forks source link

Malicious URI vulnerability #2

Closed petea closed 11 years ago

petea commented 11 years ago

Original author: Peter.A....@gmail.com (February 11, 2010 08:02:16)

Using the javascript or data scheme, it's possible to present a link to the user that, when clicked, executes javascript in the chrome security context.

Original bug report:

https://www.mozdev.org/bugs/show_bug.cgi?id=20610

Original issue: http://code.google.com/p/sage/issues/detail?id=2

petea commented 11 years ago

From Peter.A....@gmail.com on March 08, 2010 22:05:49 This issue was closed by revision 841c04a34a.