Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly restrict read access to object properties in showModalDialog, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via crafted dialogArguments values.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2010-02-22 05:00
Updated : 2017-09-18 18:29
NVD link : CVE-2009-3988
Mitre link : CVE-2009-3988
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
mozilla
- firefox
- seamonkey