4.3
CVSSv2

CVE-2009-1724

Published: 09/07/2009 Updated: 09/08/2022
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari prior to 4.0.2, as used on iPhone OS prior to 3.1, iPhone OS prior to 3.1.1 for iPod touch, and other platforms, allows remote malicious users to inject arbitrary web script or HTML via vectors related to parent and top objects.

Vulnerable Product Search on Vulmon Subscribe to Product

apple safari 3.0.4b

apple safari 2.0.3

apple safari

apple safari 3.0.4

apple safari 3.0.1

apple safari 2.0.1

apple safari 2.0.2

apple safari 3.0.0

apple safari 3.2.2

apple safari 3.0.3b

apple safari 3.0.3

apple safari 3.1.2

apple safari 3.0.2

apple safari 2.0.4

apple safari 2.0.0

apple safari 2.0

apple safari 3.1.1

apple safari 3.1.0b

apple safari 4.0.0b

apple safari 4.0

apple safari 3.1.0

apple safari 3.0.0b

apple safari 3.2.1

apple safari 3.0

apple safari 3.2.0

apple safari 3.0.2b

apple safari 3.0.1b

apple iphone_os 3.0

apple iphone_os 1.0.2

apple iphone_os 2.2

apple iphone_os

apple iphone_os 1.1.1

apple iphone_os 2.0.0

apple iphone_os 1.1.2

apple iphone_os 1.1.3

apple iphone_os 1.1.0

apple iphone_os 2.2.1

apple iphone_os 1.1.5

apple iphone_os 1.1.4

apple iphone_os 1.0.0

apple iphone_os 2.1.1

apple iphone_os 2.1

apple iphone_os 2.0.2

apple iphone_os 2.0.1

apple iphone_os 2.0

apple iphone_os 1.0.1

apple iphone_os 3.0.1

apple ipod_touch

Vendor Advisories

Debian Bug report logs - #538402 CVE-2009-1724: Cross-site scripting (XSS) vulnerability in WebKit Package: webkit; Maintainer for webkit is (unknown); Reported by: Luciano Bello <luciano@debianorg> Date: Sat, 25 Jul 2009 15:24:01 UTC Severity: grave Tags: security Found in version 1110-2 Fixed in version webkit/1113 ...

Exploits

source: wwwsecurityfocuscom/bid/35441/info WebKit is prone to a cross-domain scripting vulnerability A remote attacker can exploit this vulnerability to bypass the same-origin policy and obtain potentially sensitive information or launch spoofing attacks against other sites Other attacks are also possible <iframe src="www ...