8.8
CVSSv2

CVE-2011-1774

Published: 21/07/2011 Updated: 14/02/2012
CVSS v2 Base Score: 8.8 | Impact Score: 9.2 | Exploitability Score: 8.6
VMScore: 885
Vector: AV:N/AC:M/Au:N/C:N/I:C/A:C

Vulnerability Summary

WebKit in Apple Safari prior to 5.0.6 has improper libxslt security settings, which allows remote malicious users to create arbitrary files, and consequently execute arbitrary code, via a crafted web site. NOTE: this may overlap CVE-2011-1425.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple safari 1.2.4

apple safari 1.2.2

apple safari 1.1.1

apple safari 1.0

apple safari 1.1.0

apple safari 1.0.1

apple safari 3.0.0

apple safari 2.0.3

apple safari 1.3.0

apple safari 1.2.1

apple safari 1.0.3

apple safari 1.2.5

apple safari 3.0

apple safari 3.0.1

apple safari 5.0

apple safari 3

apple safari 1.3.2

apple safari 5.0.2

apple safari 4.1.1

apple safari 3.0.4

apple safari 3.0.2b

apple safari 1.2.3

apple safari 1.3.1

apple safari 1.0.0b1

apple safari 1.0.0b2

apple safari 3.0.0b

apple safari 5.0.1

apple safari 3.0.3b

apple safari 4.1.2

apple safari 3.1.1

apple safari 3.2.2

apple safari 3.1.0b

apple safari 3.1.2

apple safari 5.0.3

apple safari 2.0.4

apple safari 2

apple safari 1.2

apple safari 2.0.0

apple safari 3.0.1b

apple safari 1.1

apple safari 3.2.0

apple safari 3.1.0

apple safari 5.0.4

apple safari

apple safari 2.0.1

apple safari 2.0.2

apple safari 1.2.0

apple safari 1.0.2

apple safari 1.0.0

apple safari 1.3

apple safari 3.0.3

apple safari 2.0

apple safari 3.2.1

apple safari 4.1

apple safari 3.0.4b

apple safari 3.0.2

apple webkit

Exploits

## # $Id: safari_xslt_outputrb 13987 2011-10-18 07:39:50Z sinn3r $ ## ## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # Framework web site for more information on licensing and terms of use # metasploitcom/framework/ ## require 'msf/core' c ...