关键信息 漏洞编号: Mozilla Foundation Security Advisory 2009-18 漏洞类型: XSS (Cross-Site Scripting) Hazard using third-party stylesheets and XBL bindings 公告日期: April 21, 2009 报告者: Cefn Hoile 影响级别: Low 受影响产品: Firefox 修复版本: Firefox 3.0.9 描述 Web developers who incorporate the ability for users to embed third-party stylesheets on their websites are vulnerable to script injection attacks via XBL bindings. This risk was already noted, but some developers were not fully aware of it. To prevent this, Mozilla has imposed a rule that XBL bindings must originate from the same source as the document to which they are applied. Websites using Thunderbird, which shares its browser engine with Firefox, could be at risk if JavaScript is activated in emails. This is not a standard setup, so we strongly advise against activating JavaScript in emails. 参考资料 Bugzilla Link: https://bugzilla.mozilla.org/show_bug.cgi?id=481558 CVE Identifier: CVE-2009-1308