PT-2007-1938 · Apple · Webcore

Published

2007-01-25

·

Updated

2018-10-16

·

CVE-2007-0478

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions WebCore versions 10.3.9 through 10.4.10
Description The issue allows remote attackers to conduct cross-site scripting (XSS) attacks by embedding certain HTML tags within an HTML comment in TITLE elements, which can bypass some XSS protection schemes.
Recommendations For versions 10.3.9 through 10.4.10, consider disabling the parsing of HTML comments in TITLE elements as a temporary workaround until a patch is available. Restrict access to potentially vulnerable WebCore components to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-0478

Affected Products

Webcore