UI Redressing Mayhem series is going to illustrate the results of my research, presenting 0day exploiting techniques and several vulnerabilities that involve high-profile web applications. Each post of the series will also provide detailed information about the vulnerabilities and techniques, together with working Proof-of-Concept exploits. The method was tested against Mozilla Firefox version 17.0.1 – the latest stable release at the time of writing. The iframe-to-iframe method re-introduces the possibility to abuse the Firefox drag&drop mechanism to perform a cross-domain data extraction.”]
Source: http://blog.nibblesec.org/2012/12/ui-redressing-mayhem-firefox-0day-and.html