Closed
Bug 1335800
Opened 9 years ago
Closed 9 years ago
[Firefox-50.1.0] xss on webbrowser while translating the URL
Categories
(Firefox :: Untriaged, defect)
Tracking
()
RESOLVED
DUPLICATE
of bug 255107
People
(Reporter: anish2good, Unassigned)
Details
Attachments
(1 file)
|
231.65 KB,
image/jpeg
|
Details |
User Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_2) AppleWebKit/602.3.12 (KHTML, like Gecko) Version/10.0.2 Safari/602.3.12
Steps to reproduce:
open this on the webborwser
data:html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4=
Actual results:
XSS will Fired
Expected results:
In Chrome & Safari No XSS is Fired
Comment 1•9 years ago
|
||
This is a known difference in how Firefox handles data: URIs compared to other browsers.
Group: firefox-core-security
Status: UNCONFIRMED → RESOLVED
Closed: 9 years ago
Resolution: --- → DUPLICATE
You need to log in
before you can comment on or make changes to this bug.
Description
•