Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Apple Safari Cross-Domain Race Condition Information Disclosure Vulnerability

Apple Safari is prone to an information-disclosure vulnerability because it fails to properly enforce cross-domain JavaScript restrictions.

Exploiting this issue may allow attackers to access locations that a user visits, even if those locations are in a different domain than the attacker's site. The most common manifestation of this condition would typically be in blogs or forums. Attackers may be able to access potentially sensitive information that would aid in phishing attacks.

This issue affects versions prior to Safari 3 Beta Update 3.0.2







 

Privacy Statement
Copyright 2009, SecurityFocus