Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly restrict read access to object properties in showModalDialog, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via crafted dialogArguments values.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2010-02-22 13:00
Updated : 2017-09-19 01:29
NVD link : CVE-2009-3988
Mitre link : CVE-2009-3988
CVE.ORG link : CVE-2009-3988
JSON object : View
Products Affected
mozilla
- seamonkey
- firefox
CWE
CWE-264
Permissions, Privileges, and Access Controls