CVE-2010-1391: Path Traversal

Published Jun 11, 2010
·
Updated

Multiple directory traversal vulnerabilities in the (a) Local Storage and (b) Web SQL database implementations in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allow remote attackers to create arbitrary database files via vectors involving a (1) %2f and .. (dot dot) or (2) %5c and .. (dot dot) in a URL.

Affected Software

113 affected components
Apple Safari<=4.0.5
Apple Safari=4.0
Apple Safari=4.0.0b
Apple Safari=4.0.1
Apple Safari=4.0.2
Apple Safari=4.0.3
Apple Safari=4.0.4
Apple WebKit
Apple iOS and macOS=10.5
Apple iOS and macOS=10.5.0
Apple iOS and macOS=10.5.1
Apple iOS and macOS=10.5.2
Apple iOS and macOS=10.5.3
Apple iOS and macOS=10.5.4
Apple iOS and macOS=10.5.5
Apple iOS and macOS=10.5.6
Apple iOS and macOS=10.5.7
Apple iOS and macOS=10.5.8
Apple iOS and macOS=10.6.0
Apple iOS and macOS=10.6.1
Apple iOS and macOS=10.6.2
Apple iOS and macOS=10.6.3
Apple Mac OS X Server=10.5
Apple Mac OS X Server=10.5.0
Apple Mac OS X Server=10.5.1
Apple Mac OS X Server=10.5.2
Apple Mac OS X Server=10.5.3
Apple Mac OS X Server=10.5.4
Apple Mac OS X Server=10.5.5
Apple Mac OS X Server=10.5.6
Apple Mac OS X Server=10.5.7
Apple Mac OS X Server=10.5.8
Apple Mac OS X Server=10.6.0
Apple Mac OS X Server=10.6.1
Apple Mac OS X Server=10.6.2
Apple Mac OS X Server=10.6.3
Microsoft Windows 7
Microsoft Windows Vista
Microsoft Windows XP=sp2
Microsoft Windows XP=sp3
Apple iOS and macOS=10.4
Apple iOS and macOS=10.4.0
Apple iOS and macOS=10.4.1
Apple iOS and macOS=10.4.2
Apple iOS and macOS=10.4.3
Apple iOS and macOS=10.4.4
Apple iOS and macOS=10.4.5
Apple iOS and macOS=10.4.6
Apple iOS and macOS=10.4.7
Apple iOS and macOS=10.4.8
Apple iOS and macOS=10.4.9
Apple iOS and macOS=10.4.10
Apple iOS and macOS=10.4.11
Apple Mac OS X Server=10.4
Apple Mac OS X Server=10.4.0
Apple Mac OS X Server=10.4.1
Apple Mac OS X Server=10.4.2
Apple Mac OS X Server=10.4.3
Apple Mac OS X Server=10.4.4
Apple Mac OS X Server=10.4.5
Apple Mac OS X Server=10.4.6
Apple Mac OS X Server=10.4.7
Apple Mac OS X Server=10.4.8
Apple Mac OS X Server=10.4.9
Apple Mac OS X Server=10.4.10
Apple Mac OS X Server=10.4.11
All of the following
Any of the following
Apple Safari<=4.0.5
Apple Safari=4.0
Apple Safari=4.0.0b
Apple Safari=4.0.1
Apple Safari=4.0.2
Apple Safari=4.0.3
Apple Safari=4.0.4
Apple WebKit
Any of the following
Apple Mac OS X Server=10.5
Apple Mac OS X Server=10.5.0
Apple Mac OS X Server=10.5.1
Apple Mac OS X Server=10.5.2
Apple Mac OS X Server=10.5.3
Apple Mac OS X Server=10.5.4
Apple Mac OS X Server=10.5.5
Apple Mac OS X Server=10.5.6
Apple Mac OS X Server=10.5.7
Apple Mac OS X Server=10.5.8
Apple Mac OS X Server=10.6.0
Apple Mac OS X Server=10.6.1
Apple Mac OS X Server=10.6.2
Apple Mac OS X Server=10.6.3
Microsoft Windows 7
Microsoft Windows Vista
Microsoft Windows XP=sp2
Microsoft Windows XP=sp3
All of the following
Any of the following
Apple Safari<=4.0.5
Apple Safari=4.0
Apple Safari=4.0.0b
Apple Safari=4.0.1
Apple Safari=4.0.2
Apple Safari=4.0.3
Apple Safari=4.0.4
Apple WebKit
Any of the following
Apple Mac OS X Server=10.4
Apple Mac OS X Server=10.4.0
Apple Mac OS X Server=10.4.1
Apple Mac OS X Server=10.4.2
Apple Mac OS X Server=10.4.3
Apple Mac OS X Server=10.4.4
Apple Mac OS X Server=10.4.5
Apple Mac OS X Server=10.4.6
Apple Mac OS X Server=10.4.7
Apple Mac OS X Server=10.4.8
Apple Mac OS X Server=10.4.9
Apple Mac OS X Server=10.4.10
Apple Mac OS X Server=10.4.11

Event History

Jun 11, 2010
CVE Published
via MITRE·05:28 PM
Data Sourced
via MITRE·05:28 PM
Description
Data Sourced
06:00 PM
DescriptionWeaknessAffected Software
Data Sourced
via NVD·06:00 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2010-1391?

CVE-2010-1391 is classified as a high severity vulnerability due to the potential for remote attackers to exploit directory traversal issues.

2

How do I fix CVE-2010-1391?

To address CVE-2010-1391, update to the latest version of Apple Safari that is not affected, specifically Safari version 5.0 or higher.

3

What systems are affected by CVE-2010-1391?

CVE-2010-1391 affects multiple versions of Apple Safari prior to 5.0 on Mac OS X and Windows systems.

4

What kind of attacks can exploit CVE-2010-1391?

Attackers can exploit CVE-2010-1391 to create arbitrary database files through directory traversal vulnerabilities in WebKit.

5

Is CVE-2010-1391 still a risk for users today?

CVE-2010-1391 poses no risk to users who have updated to Safari 5.0 or later, as it was addressed in subsequent releases.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203