User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.7.7) Gecko/20050414 Firefox/1.0.3 Build Identifier: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.7.7) Gecko/20050414 Firefox/1.0.3 chrome privileges Reproducible: Always Steps to Reproduce: url Actual Results: getting owned Expected Results: not getting owned may need to exit mozilla and reload testcase.
Confirmed. This is fixed by the patch for bug 290949 (which was accidentally attached to bug 290982). I'll mark it as a dependent bug instead of dupe so we don't forget to retest, just in case that patch evolves into something that doesn't fix it.
Created attachment 181305 [details] testcase that works previous version suffered from save-as escaped url.
sometimes you need to clear the cache to get the testcase to work.
bug 290949 isn't blocking 1.8b2. Should this be?
*** Bug 292894 has been marked as a duplicate of this bug. ***
Clearing security flag from announced vulnerabilities fixed in Firefox 1.0.4/Mozilla 1.7.8