PT-2007-5612 · Apple · Safari

Gareth Heyes

+1

·

Publicado

2007-08-20

·

Atualizado

2008-11-15

·

CVE-2007-4431

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Apple Safari for Windows versions 3.0.3 and earlier
Description The issue allows remote attackers to bypass the Same Origin Policy, enabling access from local zones to external domains. This is achieved via a certain body.innerHTML property value, which facilitates a classic JavaScript frame hijacking attack.
Recommendations For Apple Safari for Windows versions 3.0.3 and earlier, update to a version later than 3.0.3 to resolve the issue.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-4431

Produtos afetados

Safari