First published: Thu Jan 25 2007(Updated: )
WebCore on Apple Mac OS X 10.3.9 and 10.4.10, as used in Safari, does not properly parse HTML comments in TITLE elements, which allows remote attackers to conduct cross-site scripting (XSS) attacks and bypass some XSS protection schemes by embedding certain HTML tags within an HTML comment.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS and macOS | =10.3.9 | |
Apple iOS and macOS | =10.4.10 | |
Safari | ||
Apple WebCore |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-0478 is considered a moderate severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2007-0478, users should update to the latest version of Safari or Mac OS X that addresses this vulnerability.
CVE-2007-0478 allows remote attackers to conduct cross-site scripting (XSS) attacks.
CVE-2007-0478 affects Apple Safari and Apple WebCore on Mac OS X 10.3.9 and 10.4.10.
Exploitation of CVE-2007-0478 can be achieved by embedding HTML tags within HTML comments to bypass XSS protection.