Description
Cross-domain vulnerability in Apple Safari for Windows 3.0.3 and earlier allows remote attackers to bypass the Same Origin Policy, with access from local zones to external domains, via a certain body.innerHTML property value, aka "classic JavaScript frame hijacking."
References (5)
Core 5
Core References
Various Sources x_refsource_misc
http://sla.ckers.org/forum/read.php?3%2C14151
Various Sources x_refsource_misc
http://www.thespanner.co.uk/2007/08/17/safari-beta-zero-day/
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/46720
Exploit x_refsource_misc
http://www.0x000000.com/index.php?i=420
Exploit vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/25355
Scores
EPSS
0.0134
EPSS Percentile
68.5%
Details
Status
published
Products (1)
apple/safari
< 3.0.3
Published
Aug 20, 2007
Tracked Since
Feb 18, 2026