10
CVSSv2

CVE-2007-2843

Published: 24/05/2007 Updated: 15/11/2008
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Cross-domain vulnerability in Apple Safari 2.0.4 allows remote malicious users to access restricted information from other domains via Javascript, as demonstrated by a js script that accesses the location information of cross-domain web pages, probably involving setTimeout and timed events.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple safari 2.0.4

Exploits

source: wwwsecurityfocuscom/bid/24121/info Apple Safari is prone to an information-disclosure vulnerability because it fails to properly enforce cross-domain JavaScript restrictions Exploiting this issue may allow attackers to access locations that a user visits, even if it's in a different domain than the attacker's site The most comm ...