Mozilla Foundation Security Advisory 2005-35 Showing blocked javascript: popup uses wrong privilege context Announced: April 15, 2005 Reporter: Doron Rosenberg Impact: Moderate Products: Firefox, Mozilla Suite Fixed in: Firefox 1.0.3, Mozilla Suite 1.7.7 Description When a popup is blocked, the user is given the ability to open that one popup through the popup-blocking status bar icon and, in Firefox, through the infobar. If the popup URL were javascript: selecting "Show javascript:..." from the infobar or popup blocking status bar menus would run the javascript with elevated privileges which could be used to install malicious software. Workaround Do not show blocked popups, or, if you must, show individual popups only if the menu item starts with "Show http://" or "Show https://" References https://bugzilla.mozilla.org/show_bug.cgi?id=289204