PT-2008-3520 · Apple · Safari
Published
2008-04-28
·
Updated
2018-10-11
·
CVE-2008-1999
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Apple Safari version 3.1.1
Description
The issue allows remote attackers to spoof the address bar by placing many "invisible" characters in the userinfo subcomponent of the authority component of the URL, specifically in the user field. This can be achieved by using sequences such as
%E3%80%80.Recommendations
For Apple Safari version 3.1.1, update to a newer version to mitigate the risk of address bar spoofing.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Safari