First published: Thu Jan 25 2007(Updated: )
WebCore on Apple Mac OS X 10.3.9 and 10.4.10, as used in Safari, does not properly parse HTML comments in TITLE elements, which allows remote attackers to conduct cross-site scripting (XSS) attacks and bypass some XSS protection schemes by embedding certain HTML tags within an HTML comment.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mac OS X | =10.3.9 | |
Apple Mac OS X | =10.4.10 | |
Apple Safari | ||
Apple Webcore |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.