Apple Safari prior to 5.0 on Mac OS X 10.5 up to and including 10.6 and Windows, and prior to 4.1 on Mac OS X 10.4, does not provide a warning about a (1) http or (2) https URL that contains a username and password, which makes it easier for remote malicious users to conduct phishing attacks via a crafted URL.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
apple safari |
||
apple safari 4.0 |
||
apple safari 4.0.0b |
||
apple safari 4.0.1 |
||
apple safari 4.0.2 |
||
apple safari 4.0.3 |
||
apple safari 4.0.4 |