vendor:
Safari
by:
Chris
7.5
CVSS
HIGH
Information Disclosure
200
CWE
Product Name: Safari
Affected Version From: Safari prior to version 4
Affected Version To: Safari 4
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2009
WebKit Remote Information Disclosure Vulnerability
An attacker can exploit this issue to obtain sensitive information that may aid in further attacks. Safari prior to version 4 may permit an evil web page to steal files from the local system. This is accomplished by mounting an XXE attack against the parsing of the XSL XML. To mount the attack, the attacker would serve a web page which has XML MIME type and requests to be styled by the evil stylesheet.
Mitigation:
Upgrade to the latest version of Safari.