Secunia Logo
 
CVE Reference: CVE-2007-2843
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-2843

Description:
Cross-domain vulnerability in Apple Safari 2.0.4 allows remote attackers to access restricted information from other domains via Javascript, as demonstrated by a js script that accesses the location information of cross-domain web pages, probably involving setTimeout and timed events.

CVE Status:
Candidate

References:

OSVDB
  38859

MISC
  http://www.thespanner.co.uk/2007/05/18/safari-needs-fixing/
  http://www.businessinfo.co.uk/labs/googlesnoop/snoop.html

BID
  24121


Return to the previous page.