CVE-2011-3218

Apple Mac OS X < 10.6.8 - XSS

Title source: rule

Description

The "Save for Web" selection in QuickTime Player in Apple Mac OS X through 10.6.8 exports HTML documents that contain an http link to a script file, which allows man-in-the-middle attackers to conduct cross-site scripting (XSS) attacks by spoofing the http server during local viewing of an exported document.

Scores

EPSS 0.0066
EPSS Percentile 70.9%

Classification

CWE
CWE-79
Status published

Affected Products (50)

apple/mac_os_x < 10.6.8
apple/mac_os_x
apple/mac_os_x
apple/mac_os_x
apple/mac_os_x
apple/mac_os_x
apple/mac_os_x
apple/mac_os_x
apple/mac_os_x
apple/mac_os_x
apple/mac_os_x
apple/mac_os_x
apple/mac_os_x
apple/mac_os_x
apple/mac_os_x
... and 35 more

Timeline

Published Oct 14, 2011
Tracked Since Feb 18, 2026