PT-2007-1938 · Apple · Webcore
Published
2007-01-25
·
Updated
2018-10-16
·
CVE-2007-0478
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
WebCore versions 10.3.9 through 10.4.10
Description
The issue allows remote attackers to conduct cross-site scripting (XSS) attacks by embedding certain HTML tags within an HTML comment in TITLE elements, which can bypass some XSS protection schemes.
Recommendations
For versions 10.3.9 through 10.4.10, consider disabling the parsing of HTML comments in TITLE elements as a temporary workaround until a patch is available. Restrict access to potentially vulnerable WebCore components to minimize the risk of exploitation.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Webcore