Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari prior to 5.0 on Mac OS X 10.5 up to and including 10.6 and Windows, and prior to 4.1 on Mac OS X 10.4, allows remote malicious users to inject arbitrary web script or HTML via a FRAME element with a SRC attribute composed of a javascript: sequence preceded by spaces.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
apple safari 4.0.3 |
||
apple safari |
||
apple safari 4.0.0b |
||
apple safari 4.0 |
||
apple safari 4.0.4 |
||
apple webkit |
||
apple safari 4.0.2 |
||
apple safari 4.0.1 |