First published: Thu Feb 10 2005(Updated: )
Apple Safari 1.2.4 does not obey the Content-type field in the HTTP header and renders text as HTML, which allows remote attackers to inject arbitrary web script or HTML and perform cross-site scripting (XSS) attacks.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Safari | =1.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0341 has been classified as a high severity vulnerability due to its potential for enabling cross-site scripting (XSS) attacks.
To fix CVE-2005-0341, update to a newer version of Safari that addresses this vulnerability.
CVE-2005-0341 can lead to cross-site scripting (XSS) attacks, allowing attackers to inject arbitrary web scripts or HTML.
CVE-2005-0341 specifically affects Apple Safari version 1.2.4.
While CVE-2005-0341 pertains to an older version of Safari, users of outdated software may still be at risk if they run this version.