|
The Fizzle add-on for Mozilla Firefox contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate RSS feed data upon converting HTML entity code back into ASCII equivalents. This could allow a user to create a specially crafted feed that would execute untrusted code in a user's browser within a trusted context of the browser, leading to a loss of integrity.
|