Vulnerability Name: | CVE-2008-1003 (CCN-41334) | ||||||||
Assigned: | 2008-03-18 | ||||||||
Published: | 2008-03-18 | ||||||||
Updated: | 2017-08-08 | ||||||||
Summary: | Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple Safari before 3.1, allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to sites that set the document.domain property or have the same document.domain. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-79 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2008-1003 Source: CCN Type: Apple Web site About the security content of Safari 3.1 Source: CONFIRM Type: UNKNOWN http://docs.info.apple.com/article.html?artnum=307563 Source: APPLE Type: Patch APPLE-SA-2008-03-18 Source: CCN Type: SA29393 Apple Safari Multiple Vulnerabilities Source: SECUNIA Type: UNKNOWN 29393 Source: CCN Type: SECTRACK ID: 1019653 Safari Multiple Input Validation and Processing Bugs Permit Cross-Site Scripting Attacks Source: CCN Type: OSVDB ID: 43360 Apple Safari WebCore document.domain property Unspecified XSS Source: BID Type: UNKNOWN 28290 Source: CCN Type: BID-28290 RETIRED: Apple Safari Prior to 3.1 Multiple Security Vulnerabilities Source: BID Type: UNKNOWN 28330 Source: CCN Type: BID-28330 Apple Safari WebCore 'document.domain' Cross-Site Scripting Vulnerability Source: SECTRACK Type: UNKNOWN 1019653 Source: CERT Type: US Government Resource TA08-079A Source: VUPEN Type: UNKNOWN ADV-2008-0920 Source: XF Type: UNKNOWN safari-documentdomain-security-bypass(41334) Source: XF Type: UNKNOWN safari-documentdomain-security-bypass(41334) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |