CVE-2011-3426: XSS
Cross-site scripting (XSS) vulnerability in Safari in Apple iOS before 5 allows remote web servers to inject arbitrary web script or HTML via a file accompanied by a "Content-Disposition: attachment" HTTP header.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3426?
The severity of CVE-2011-3426 is categorized as moderate due to its ability to facilitate cross-site scripting attacks.
How do I fix CVE-2011-3426?
To fix CVE-2011-3426, you should upgrade to iOS version 5 or later where the vulnerability has been addressed.
What systems are affected by CVE-2011-3426?
CVE-2011-3426 affects Apple iOS versions 4.0, 4.0.1, 4.0.2, 4.1, 4.2.x, 4.3.x, and earlier.
What type of attack is possible with CVE-2011-3426?
CVE-2011-3426 allows remote web servers to inject arbitrary web script or HTML into Safari on affected devices.
Is CVE-2011-3426 still a concern today?
CVE-2011-3426 is less of a concern for users on current iOS versions, but still poses a risk for those using outdated systems.