It appears this is not really a coding bug in the Mozilla software. Rather, they forgot to block a feature of Windows that can use the shell: handler. Actually, Firefox (and friends) try to be nice a offer all external protocol handlers registered to Windows (such as eg. aim:). Apparently windows itself offers something called shell: that can be use to fire commands and the Mozilla coders forgot to block the access from the browser to it.
mayeb this'll make some people feel better *grin*
Date: 2004-07-11 05:53 am (UTC)