First published: Mon Aug 20 2007(Updated: )
Cross-domain vulnerability in Apple Safari for Windows 3.0.3 and earlier allows remote attackers to bypass the Same Origin Policy, with access from local zones to external domains, via a certain body.innerHTML property value, aka "classic JavaScript frame hijacking."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mobile Safari | <=3.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-4431 is considered a moderate severity vulnerability due to its potential for cross-domain exploitation.
To mitigate CVE-2007-4431, users should update their Apple Safari browser to a version later than 3.0.3.
CVE-2007-4431 enables attackers to perform classic JavaScript frame hijacking, allowing access across different domains.
Users of Apple Safari for Windows version 3.0.3 and earlier are specifically affected by CVE-2007-4431.
CVE-2007-4431 exploits the Same Origin Policy by allowing access from local zones to external domains through manipulated JavaScript.