CVE-2007-5854: XSS
Published Dec 19, 2007
·Updated
Launch Services in Apple Mac OS X 10.4.11 and 10.5.1 does not treat HTML files as unsafe content, which allows attackers to conduct cross-site scripting (XSS) attacks or obtain sensitive information via a crafted HTML file.
Affected Software
2 affected components
Apple iOS and macOS=10.5.1
Apple iOS and macOS=10.4.11
Event History
Dec 19, 2007
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What must an attacker do to exploit this issue?
An attacker must provide or induce a user to open a crafted HTML file. The vulnerable handling of that file can enable cross-site scripting or disclosure of sensitive information.
2
Is authentication required for exploitation?
No. The supplied vector indicates network-based exploitation with no authentication required, although exploitation depends on the victim handling a crafted HTML file.
3
Which Mac OS X versions are identified as affected?
The description specifically identifies Apple Mac OS X 10.4.11 and 10.5.1.