PT-2007-4147 · Apple · Safari
Gareth Heyes
+1
·
Published
2007-05-24
·
Updated
2008-11-15
·
CVE-2007-2843
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Apple Safari version 2.0.4
Description
A cross-domain issue allows remote attackers to access restricted information from other domains via Javascript. This can be achieved through a js script that accesses the location information of cross-domain web pages, possibly involving
setTimeout and timed events.Recommendations
For Apple Safari version 2.0.4, consider disabling Javascript execution for cross-domain requests as a temporary workaround until a patch is available. Restrict access to sensitive information to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Safari