Improves detection of free inline script injections

May 31, 2012 09:25 GMT  ·  By

The change log for the latest version of NoScript, the Firefox extension that prevents scripts from loading on the web page, comprises fixes and improvements.

NoScript 2.4.3 improves protection against XSS (cross-site-scripting) by adding better detection of free inline script injections inside function calls. On the same note, the “noscript.allowedMimeRegExp” preference now applies also to Java, Flash and Silverlight mime types.

The repairs available in this release consist in fixing JavaScript links detection that would not resolve JavaScript string escapes and the HTML 5 parser detection in META refresh processing was broken by a removed browser preference.

Additionally, the exception raised by including type checks when parent document's URI has no host should no longer be a problem.

NoScript extension for Firefox is available for download on this page.