First published: Fri Jul 23 2004(Updated: )
Safari 1.2.2 does not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mobile Safari | =1.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0720 is classified as a moderate severity vulnerability due to its potential for web site spoofing and frame injection attacks.
To mitigate CVE-2004-0720, it is recommended to upgrade to a later version of Safari that does not have this vulnerability.
CVE-2004-0720 specifically affects Apple Safari version 1.2.2.
CVE-2004-0720 can facilitate attacks such as web site spoofing and unauthorized content injection into web pages.
A workaround for CVE-2004-0720 is to avoid using Safari 1.2.2 and instead use a more secure browser until an update can be applied.