vendor:
Safari
by:
SecurityFocus
7,5
CVSS
HIGH
URI-spoofing
451
CWE
Product Name: Safari
Affected Version From: Apple Safari 5.1.5 and prior
Affected Version To: Apple Safari 5.1.5 and prior
Patch Exists: YES
Related CWE: N/A
CPE: a:apple:safari
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2012
Apple Safari for Windows URI-spoofing Vulnerability
Apple Safari for Windows is affected by a URI-spoofing vulnerability. An attacker may leverage this issue to spoof the source URI of a site presented to an unsuspecting user. This may lead to a false sense of trust because the user may be presented with a source URI of a trusted site while interacting with the attacker's malicious site.
Mitigation:
Upgrade to Apple Safari 5.1.5 or later.