CVE-2007-4431

Apple Safari for Windows <3.0.3 - CSRF

Title source: llm
STIX 2.1

Description

Cross-domain vulnerability in Apple Safari for Windows 3.0.3 and earlier allows remote attackers to bypass the Same Origin Policy, with access from local zones to external domains, via a certain body.innerHTML property value, aka "classic JavaScript frame hijacking."

References (5)

Core 5
Core References
Various Sources x_refsource_misc
http://sla.ckers.org/forum/read.php?3%2C14151
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/46720
Exploit x_refsource_misc
http://www.0x000000.com/index.php?i=420
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/25355

Scores

EPSS 0.0134
EPSS Percentile 68.5%

Details

Status published
Products (1)
apple/safari < 3.0.3
Published Aug 20, 2007
Tracked Since Feb 18, 2026