98474vdb entry
http://www.securityfocus.com/bid/98474 CVE-2017-2508
MEDIUM
WebKit - 'ContainerNode::parserInsertBefore' Universal Cross-Site Scripting
Record summary
CVE-2017-2508 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit.
Description
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that improperly interacts with container nodes.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBWebKit - 'ContainerNode::parserInsertBefore' Universal Cross-Site ScriptingExploitDB exploitby Google Security ResearchNot analyzed1 file
References
71038487vdb entry
http://www.securitytracker.com/id/1038487 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-2508 GLSA-201706-15Vendor advisory
https://security.gentoo.org/glsa/201706-15 support.apple.comConfirmation
https://support.apple.com/HT207798 support.apple.comConfirmation
https://support.apple.com/HT207804 42066exploit
https://www.exploit-db.com/exploits/42066