vendor:
Safari
by:
Juan Pablo Lopez Yacubian
7.5
CVSS
HIGH
Content Spoofing
80
CWE
Product Name: Safari
Affected Version From: 3.1
Affected Version To: 3.1
Patch Exists: YES
Related CWE: N/A
CPE: a:apple:safari
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Microsoft Windows
2008
Apple Safari Content Spoofing Vulnerability
Apple Safari is prone to a content-spoofing vulnerability that allows attackers to populate a vulnerable Safari browser window with arbitrary malicious content. During such an attack, the URL and window title will display the intended site, while the body of the webpage is spoofed. Safari 3.1 running on Microsoft Windows is reported vulnerable.
Mitigation:
Users should exercise caution when visiting untrusted websites and should not click on suspicious links.