source: https://www.securityfocus.com/bid/16427/info Mozilla Firefox is prone to a security vulnerability that may let a Web page execute malicious script code in the context of an arbitrary domain. The issue affects the '-moz-binding' property. This could allow a malicious site to access the properties of a trusted site and facilitate various attacks including disclosure of sensitive information. http://domain1/path/to/page.html : http://domain2/path/to/xbl.xml : alert("XBL XSS");