CVE-2005-0341
Apple Safari 1.2.4 - Cross-Site Scripting via HTTP Content-Type Header Mismatch
Title source: llmDescription
Apple Safari 1.2.4 does not obey the Content-type field in the HTTP header and renders text as HTML, which allows remote attackers to inject arbitrary web script or HTML and perform cross-site scripting (XSS) attacks.
References (4)
Core 4
Core References
Mailing List mailing-list
x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=110756965213819&w=2
Exploit, Vendor Advisory x_refsource_misc
http://tigger.uic.edu/~jrockw2/safari_20050204.txt
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/19227
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://securitytracker.com/id?1013087
Scores
EPSS
0.0126
EPSS Percentile
66.5%
Details
Status
published
Products (1)
apple/safari
1.2.4
Published
May 02, 2005
Tracked Since
Feb 18, 2026