Secunia Logo
 
CVE Reference: CVE-2008-0060
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2008-0060

Description:
Help Viewer in Apple Mac OS X 10.4.11 and 10.5.2 allows remote attackers to execute arbitrary Applescript via a help:topic_list URL that injects HTML or JavaScript into a topic list page, as demonstrated using a help:runscript link.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/41295

ST
  1019657

SAID
  Secunia Advisory: SA29420

CONFIRM
  http://docs.info.apple.com/article.html?artnum=307562

CERT
  http://www.us-cert.gov/cas/techalerts/TA08-079A.html

BID
  28304
  28371

APPLE
  http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html


Return to the previous page.