The view-source: URI implementation in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey does not properly implement the Same Origin Policy, which allows remote attackers to (1) bypass crossdomain.xml restrictions and connect to arbitrary web sites via a Flash file; (2) read, create, or modify Local Shared Objects via a Flash file; or (3) bypass unspecified restrictions and render content via vectors involving a jar: URI.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-07T05:04:49.691Z
Reserved: 2009-04-16T00:00:00
Link: CVE-2009-1307

No data.

Status : Modified
Published: 2009-04-22T18:30:00.297
Modified: 2024-11-21T01:02:09.303
Link: CVE-2009-1307
