Vulnerability Name:

CVE-2007-0478 (CCN-31846)

Assigned:2007-01-23
Published:2007-01-23
Updated:2018-10-16
Summary:WebCore on Apple Mac OS X 10.3.9 and 10.4.10, as used in Safari, does not properly parse HTML comments in TITLE elements, which allows remote attackers to conduct cross-site scripting (XSS) attacks and bypass some XSS protection schemes by embedding certain HTML tags within an HTML comment.
CVSS v3 Severity:4.8 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
4.0 Medium (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:N)
3.5 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:N/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-79
Vulnerability Consequences:Gain Access
References:Source: CCN
Type: BugTraq Mailing List, Tue Jan 23 2007 - 01:44:13 CST
Safari Improperly Parses HTML Documents & BlogSpot XSS vulnerability

Source: CCN
Type: BugTraq Mailing List, Tue Jan 23 2007 - 23:06:34 CST
Re: Safari Improperly Parses HTML Documents & BlogSpot XSS vulnerability

Source: MITRE
Type: CNA
CVE-2007-0478

Source: CCN
Type: Apple Security Update 2007-007
About Security Update 2007-007

Source: CONFIRM
Type: UNKNOWN
http://docs.info.apple.com/article.html?artnum=306172

Source: CCN
Type: Apple Web site
Apple security updates

Source: APPLE
Type: UNKNOWN
APPLE-SA-2007-07-31

Source: OSVDB
Type: UNKNOWN
32712

Source: CCN
Type: SA23893
Safari HTML Parsing Weakness and URL Information Disclosure

Source: SECUNIA
Type: Vendor Advisory
23893

Source: CCN
Type: SA26235
Mac OS X Security Update Fixes Multiple Vulnerabilities

Source: SECUNIA
Type: Vendor Advisory
26235

Source: CCN
Type: SECTRACK ID: 1018494
Mac OS X WebCore Bugs Permit Cross-Domain Scripting Attacks and Java Settings Bypass

Source: SECTRACK
Type: UNKNOWN
1018494

Source: MISC
Type: UNKNOWN
http://www.beanfuzz.com/wordpress/?p=99

Source: CCN
Type: GLSA-200703-10
KHTML: Cross-site scripting (XSS) vulnerability

Source: CCN
Type: OSVDB ID: 32712
Apple Safari HTML Comment Parsing XSS

Source: CCN
Type: OSVDB ID: 32975
KDE Konqueror KDE HTML library (kdelibs) HTML Parsing XSS

Source: BUGTRAQ
Type: UNKNOWN
20070123 Safari Improperly Parses HTML Documents & BlogSpot XSS vulnerability

Source: BID
Type: UNKNOWN
25159

Source: CCN
Type: BID-25159
Apple Mac OS X 2007-007 Multiple Security Vulnerabilities

Source: VUPEN
Type: UNKNOWN
ADV-2007-2732

Source: XF
Type: UNKNOWN
safari-html-comment-xss(31846)

Source: XF
Type: UNKNOWN
safari-html-comment-xss(31846)

Vulnerable Configuration:Configuration 1:
  • cpe:/o:apple:mac_os_x:10.3.9:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x:10.4.10:*:*:*:*:*:*:*
  • AND
  • cpe:/a:apple:safari:*:*:*:*:*:*:*:*
  • OR cpe:/a:apple:webcore:*:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:apple:webcore:*:*:*:*:*:*:*:*
  • OR cpe:/a:apple:safari:2.0.4:*:*:*:*:*:*:*
  • AND
  • cpe:/o:gentoo:linux:*:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:3.0:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2007:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2007::x86_64:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:4.0:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:4.0::x86_64:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:3.0::x86_64:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2007.1:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2007.1::x86-64:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    apple mac os x 10.3.9
    apple mac os x 10.4.10
    apple safari *
    apple webcore *
    apple webcore *
    apple safari 2.0.4
    gentoo linux *
    mandrakesoft mandrake linux corporate server 3.0
    mandrakesoft mandrake linux 2007
    mandrakesoft mandrake linux 2007
    mandrakesoft mandrake linux corporate server 4.0
    mandrakesoft mandrake linux corporate server 4.0
    mandrakesoft mandrake linux corporate server 3.0
    mandrakesoft mandrake linux 2007.1
    mandrakesoft mandrake linux 2007.1