CVE-2008-1999

Apple Safari 3.1.1 - Address Bar Spoofing via Invisible Characters in URL Userinfo

Title source: llm
STIX 2.1

Description

Apple Safari 3.1.1 allows remote attackers to spoof the address bar by placing many "invisible" characters in the userinfo subcomponent of the authority component of the URL (aka the user field), as demonstrated by %E3%80%80 sequences.

References (6)

Core 6
Core References
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/1347
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/41981
Various Sources x_refsource_misc
http://es.geocities.com/jplopezy/pruebasafari3.html
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/491192/100/0/threaded
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/3833
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/29900

Scores

EPSS 0.0141
EPSS Percentile 69.9%

Details

Status published
Products (1)
apple/safari 3.1.1
Published Apr 28, 2008
Tracked Since Feb 18, 2026