998 B
998 B
announced | fixed_in | impact | reporter | title | ||||
---|---|---|---|---|---|---|---|---|
May 30, 2007 |
|
High | moz_bug_r_a4 | XSS using addEventListener |
Description
Mozilla contributor moz_bug_r_a4 demonstrated that
the addEventListener
method could be used to inject
script into another site in violation of the browser's same-origin
policy. This could be used to access or modify private or valuable
information from that other site.
Workaround
Disable JavaScript until a fixed version can be installed.