CVE-2013-5151

Apple iOS <7 - XSS

Title source: llm

Description

Mobile Safari in Apple iOS before 7 does not prevent HTML interpretation of a document served with a text/plain content type, which allows remote attackers to conduct cross-site scripting (XSS) attacks by uploading a file.

Scores

EPSS 0.0030
EPSS Percentile 53.1%

Details

CWE
CWE-79
Status published
Products (49)
apple/iphone_os < 6.1.4
apple/iphone_os
apple/iphone_os
apple/iphone_os
apple/iphone_os
apple/iphone_os
apple/iphone_os
apple/iphone_os
apple/iphone_os
apple/iphone_os
... and 39 more
Published Sep 19, 2013
Tracked Since Feb 18, 2026