On 17 November 2009 I blogged about vulnerabilities with nsIScriptableUnescapeHTML.parseFragment() here – So much for nsIScriptableUnescapeHTML.parseFragment(). At the time, nsIScriptableUnescapeHTML.parseFragment() was being recommended by Wladimir Palant, Jorge Villalobos, and others, as the only way to display web content, within the trusted chrome context, while eliminating all potential security issues. Yeah right! Not only were...
