|
BugTraq
XMLHttpRequest file upload vulnerability Chrome 2 & Safari 3 Jun 09 2009 04:33PM pantera_bleed hotmail com (2 replies) Re: XMLHttpRequest file upload vulnerability Chrome 2 & Safari 3 Jun 09 2009 07:21PM Adrian P. (ap gnucitizen org) |
|
Privacy Statement |
Yup, this is an unfortunate, legacy property, not specific to any
particular browser; it is also fairly well-known and documented; see:
http://code.google.com/p/browsersec/wiki/Part2#Same-origin_policy
(multiple sections discussing file: access rules, including
XMLHttpRequest, DOM access, etc)
http://blog.chromium.org/2008/12/security-in-depth-local-web-pages.html
/mz
[ reply ]