Apple Safari Document.Domain Cross-Domain Same Origin Overwriting Vulnerability
BID:24700
Info
Apple Safari Document.Domain Cross-Domain Same Origin Overwriting Vulnerability
| Bugtraq ID: | 24700 |
| Class: | Origin Validation Error |
| CVE: |
CVE-2007-3482 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 28 2007 12:00AM |
| Updated: | May 07 2015 05:37PM |
| Credit: | Gareth Heyes is credited with the discovery of this vulnerability. |
| Vulnerable: |
Apple Safari 3.0.2 Beta for Windows Apple Safari 3.0.1 Beta for Windows Apple Safari 2.0.4 Apple Safari 2.0.3 Apple Safari 2.0.2 Apple Safari 2.0.1 Apple Safari Beta 2 Apple Safari 3 Beta for Windows Apple Safari 3 Beta Apple Mobile Safari 0 |
| Not Vulnerable: | |
Discussion
Apple Safari Document.Domain Cross-Domain Same Origin Overwriting Vulnerability
Apple Safari is prone to a vulnerability that permits an attacker to bypass the same-origin policy.
A successful exploit may allow the attacker to access properties of the targeted domain or aid in spoofing content. This may allow the attacker to steal potentially sensitive information or launch other attacks.
This issue affects Apple Safari 3.01; other versions may also be affected.
Apple Safari is prone to a vulnerability that permits an attacker to bypass the same-origin policy.
A successful exploit may allow the attacker to access properties of the targeted domain or aid in spoofing content. This may allow the attacker to steal potentially sensitive information or launch other attacks.
This issue affects Apple Safari 3.01; other versions may also be affected.
Exploit / POC
Apple Safari Document.Domain Cross-Domain Same Origin Overwriting Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
A proof-of-concept example by Gareth Heyes is available:
http://www.0x000000.com/hacks/crossdomain/safari_exploit.html
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
A proof-of-concept example by Gareth Heyes is available:
http://www.0x000000.com/hacks/crossdomain/safari_exploit.html
Solution / Fix
Apple Safari Document.Domain Cross-Domain Same Origin Overwriting Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Apple Safari Document.Domain Cross-Domain Same Origin Overwriting Vulnerability
References:
References:
- Safari Homepage (Apple)
- Defeating The Same Origin Policy (Apple )