CVE-2007-4431: Medium severity Safari vulnerability
Cross-domain vulnerability in Apple Safari for Windows 3.0.3 and earlier allows remote attackers to bypass the Same Origin Policy, with access from local zones to external domains, via a certain body.innerHTML property value, aka "classic JavaScript frame hijacking."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-4431?
CVE-2007-4431 is considered a moderate severity vulnerability due to its potential for cross-domain exploitation.
How do I fix CVE-2007-4431?
To mitigate CVE-2007-4431, users should update their Apple Safari browser to a version later than 3.0.3.
What types of attacks does CVE-2007-4431 enable?
CVE-2007-4431 enables attackers to perform classic JavaScript frame hijacking, allowing access across different domains.
Who is affected by CVE-2007-4431?
Users of Apple Safari for Windows version 3.0.3 and earlier are specifically affected by CVE-2007-4431.
What does CVE-2007-4431 exploit?
CVE-2007-4431 exploits the Same Origin Policy by allowing access from local zones to external domains through manipulated JavaScript.