Secunia Logo
 
CVE Reference: CVE-2005-2272
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2005-2272

Description:
Safari version 2.0 (412) does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the "Dialog Origin Spoofing Vulnerability."

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/21070

ST
  1015294

SAID
  Secunia Advisory: SA17813
  Secunia Advisory: SA15474

OSVDB
  17397

MISC
  http://secunia.com/multiple_browsers_dialog_origin_vulnerability_test/
  http://secunia.com/secunia_research/2005-12/advisory/

BID
  14011

APPLE
  http://docs.info.apple.com/article.html?artnum=302847


Return to the previous page.