4.3
CVSSv2

CVE-2008-1006

Published: 19/03/2008 Updated: 08/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple Safari prior to 3.1, allows remote malicious users to inject arbitrary web script or HTML by using the window.open function to change the security context of a web page.

Vulnerable Product Search on Vulmon Subscribe to Product

apple safari 0.9

apple safari 1.0

apple safari 2.0.2

apple safari 2.0.4

apple safari 1.1

apple safari 1.2

apple safari 3.0

apple safari 3.0.1

apple safari 0.8

apple safari 1.3.2

apple safari 2.0

apple safari 1.3

apple safari 1.3.1

apple safari 3.0.3

apple safari 3.0.4

apple safari 3.0.2