Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Apple Safari Web Browser Null Character Cookie Stealing Vulnerability

An issue has been discovered in Apple Safari, which may allow an attacker to steal cookie-based authentication credentials from a user of a vulnerable web browser. The problem is in the handling of NULL (%00) characters in URLs.

This issue may only be exploited to steal cookies set for a domain, as opposed to cookies set for a specific host in that domain. Cookies set with the secure flag can be stolen if the attacker uses SSL.







 

Privacy Statement
Copyright 2008, SecurityFocus