You are here: Known Vulnerabilities in Mozilla Products (Firefox 18.104.22.168) > MFSA 2008-05
Mozilla Foundation Security Advisory 2008-05
Title: Directory traversal via chrome: URI
Announced: February 7, 2008
Reporter: Gerry Eisenhaur
Products: Firefox, Thunderbird, SeaMonkey
Fixed in: Firefox 22.214.171.124
Mozilla researcher moz_bug_r_a4 reported that this
vulnerability could be used to steal the contents of the browser's
sessionstore.js file, which contains session cookie data
and information about currently open web pages.
Disable "flat-packaged" add-ons until a version containing these fixes can be installed.
- chrome: directory traversal
- Partial list of "flat" packaged add-ons
- Bug 413250 allows access to sessionstore.js