Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-2843. PoCs published by Gareth Heyes.
AI-analyzed exploit summary This exploit demonstrates a cross-domain JavaScript restriction bypass in Apple Safari, allowing attackers to snoop on the user's browsing history by repeatedly polling the location of a opened window. It leverages a timing-based approach to access potentially sensitive information.
Description
Cross-domain vulnerability in Apple Safari 2.0.4 allows remote attackers to access restricted information from other domains via Javascript, as demonstrated by a js script that accesses the location information of cross-domain web pages, probably involving setTimeout and timed events.
Exploits (1)
This exploit demonstrates a cross-domain JavaScript restriction bypass in Apple Safari, allowing attackers to snoop on the user's browsing history by repeatedly polling the location of a opened window. It leverages a timing-based approach to access potentially sensitive information.