Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

Apple Safari Domain Extensions Insecure Cookie Access Vulnerability

Apple Safari is prone to a vulnerability that allows attackers to set cookies for certain domain extensions.

The browser does not have any security provisions to prevent cookies from being set for extensions with embedded dots. Attackers can leverage this issue to set cookies in a manner that could aid in other web-based attacks.

Safari 3.1.2 is vulnerable; other versions may also be affected.







 

Privacy Statement
Copyright 2008, SecurityFocus