CVE-2009-1311
Mozilla Firefox before 3.0.9 and SeaMonkey before 1.1.17 allow user-assisted remote attackers to obtain sensitive information via a web page with an embedded frame, which causes POST data from an outer page to be sent to the inner frame’s URL during a SAVEMODE_FILEONLY save of the inner frame.
Date published : 2009-04-22
http://www.securityfocus.com/bid/34656
http://www.mozilla.org/security/announce/2009/mfsa2009-21.html