CVE-2005-0341

Apple Safari 1.2.4 - Cross-Site Scripting via HTTP Content-Type Header Mismatch

Title source: llm
STIX 2.1

Description

Apple Safari 1.2.4 does not obey the Content-type field in the HTTP header and renders text as HTML, which allows remote attackers to inject arbitrary web script or HTML and perform cross-site scripting (XSS) attacks.

References (4)

Core 4
Core References
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=110756965213819&w=2
Exploit, Vendor Advisory x_refsource_misc
http://tigger.uic.edu/~jrockw2/safari_20050204.txt
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/19227
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1013087

Scores

EPSS 0.0126
EPSS Percentile 66.5%

Details

Status published
Products (1)
apple/safari 1.2.4
Published May 02, 2005
Tracked Since Feb 18, 2026