PT-2009-4182 · Apple · Ios+2

Adam Barth

+1

·

Published

2009-06-10

·

Updated

2022-08-09

·

CVE-2009-1702

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Apple Safari versions prior to 4.0 iPhone OS versions 1.0 through 2.2.1 iPhone OS for iPod touch versions 1.1 through 2.2.1
Description: A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML via vectors related to improper handling of Location and History objects. This enables attackers to execute malicious scripts on affected devices.
Recommendations: For Apple Safari versions prior to 4.0, update to version 4.0 or later. For iPhone OS versions 1.0 through 2.2.1, update to a version later than 2.2.1. For iPhone OS for iPod touch versions 1.1 through 2.2.1, update to a version later than 2.2.1.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2009-1702

Affected Products

Safari
Ios
Iphone Os For Ipod Touch