CVE-2007-3186

Apple Safari Beta 3.0.1 - Remote Code Execution via Gopher URI in IFRAME SRC

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-3186. PoCs published by Thor Larholm.

AI-analyzed exploit summary This exploit leverages a protocol handler command-injection vulnerability in Apple Safari for Windows via an IFRAME element. It uses Mozilla XPCOM components to execute arbitrary commands, specifically launching 'cmd.exe' on the target system.

Description

Apple Safari Beta 3.0.1 for Windows allows remote attackers to execute arbitrary commands via shell metacharacters in a URI in the SRC of an IFRAME, as demonstrated using a gopher URI.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Thor Larholm · htmlremotewindows
https://www.exploit-db.com/exploits/30176

This exploit leverages a protocol handler command-injection vulnerability in Apple Safari for Windows via an IFRAME element. It uses Mozilla XPCOM components to execute arbitrary commands, specifically launching 'cmd.exe' on the target system.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Apple Safari for Windows (versions prior to Beta 3.0.1)
No auth needed
Prerequisites: Victim must be using a vulnerable version of Safari for Windows · Victim must visit a malicious webpage or have the exploit delivered via another vector
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (10)

Core 10
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/471176/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/38542
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/34824
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/2192
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/24434
Mailing List mailing-list x_refsource_fulldisc
http://lists.grok.org.uk/pipermail/full-disclosure/2007-June/063926.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1018224
Various Sources x_refsource_misc
http://larholm.com/2007/06/14/safari-301-released/
Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2007/Jun/msg00000.html

Scores

EPSS 0.0493
EPSS Percentile 91.0%

Details

CWE
CWE-264
Status published
Products (8)
apple/safari
apple/safari 2.0
apple/safari 2.0.1
apple/safari 2.0.2
apple/safari 2.0.3
apple/safari 2.0.4
apple/safari 3.0
apple/safari 3.0.1
Published Jun 12, 2007
Tracked Since Feb 18, 2026