Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

Apple Safari WebKit URI Handling Cross-Site Scripting Vulnerability

Apple Safari WebKit is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.

Attackers may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow attackers to steal cookie-based authentication credentials and to launch other attacks.

This issue affects versions prior to Apple Safari 3.1.1 running on the following platforms:

Mac OS X 10.4.11
Mac OS X 10.5.2
Windows XP
Windows Vista.







 

Privacy Statement
Copyright 2008, SecurityFocus