First published: Thu May 24 2007(Updated: )
Cross-domain vulnerability in Apple Safari 2.0.4 allows remote attackers to access restricted information from other domains via Javascript, as demonstrated by a js script that accesses the location information of cross-domain web pages, probably involving setTimeout and timed events.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mobile Safari | =2.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-2843 is considered a moderate severity vulnerability due to its potential for information disclosure.
The best mitigation for CVE-2007-2843 is to upgrade to a later version of Apple Safari that addresses this vulnerability.
CVE-2007-2843 specifically affects Apple Safari version 2.0.4.
CVE-2007-2843 is a cross-domain vulnerability that allows unauthorized access to restricted information through JavaScript.
An attacker could exploit CVE-2007-2843 to execute a script that retrieves the location information from cross-domain web pages.