First published: Wed Mar 19 2008(Updated: )
Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple Safari before 3.1, allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to the Web Inspector.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mobile Safari | =1.3.2 | |
Apple Mobile Safari | =3.0.4 | |
Apple Mobile Safari | =2.0.2 | |
Apple Mobile Safari | =3.0.1 | |
Apple Mobile Safari | =3.0.2 | |
Apple Mobile Safari | =1.0 | |
Apple Mobile Safari | =1.3 | |
Apple Mobile Safari | =3.0.3 | |
Apple Mobile Safari | =2.0 | |
Apple Mobile Safari | =0.8 | |
Apple Mobile Safari | =2.0.4 | |
Apple Mobile Safari | =1.1 | |
Apple Mobile Safari | =1.3.1 | |
Apple Mobile Safari | =1.2 | |
Apple Mobile Safari | =3.0 | |
Apple Mobile Safari | =0.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-1004 is classified as a medium severity vulnerability due to the potential for remote code execution via XSS attacks.
To mitigate CVE-2008-1004, users should upgrade to a patched version of Apple Safari that is newer than 3.1.
CVE-2008-1004 is a cross-site scripting (XSS) vulnerability affecting certain versions of Apple Safari.
CVE-2008-1004 affects multiple versions of Apple Safari, including versions from 0.8 to 3.0.4.
Attackers exploiting CVE-2008-1004 can inject arbitrary web scripts or HTML into the affected versions of Safari.