Record summary

CVE-2017-2508 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit.

Description

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that improperly interacts with container nodes.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBWebKit - 'ContainerNode::parserInsertBefore' Universal Cross-Site ScriptingExploitDB exploitby Google Security ResearchNot analyzed1 file
ExploitDB

PoC details

References

7