Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qwx4-rgjp-5rr6

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The tabbed browsing feature in Apple Safari 3 before Beta Update 3.0.4 on Windows, and Mac OS X 10.4 through 10.4.10, allows remote attackers to spoof HTTP authentication for other sites and possibly conduct phishing attacks by causing an authentication sheet to be displayed for a tab that is not active, which makes it appear as if it is associated with the active tab.

The tabbed browsing feature in Apple Safari 3 before Beta Update 3.0.4 on Windows, and Mac OS X 10.4 through 10.4.10, allows remote attackers to spoof HTTP authentication for other sites and possibly conduct phishing attacks by causing an authentication sheet to be displayed for a tab that is not active, which makes it appear as if it is associated with the active tab.

EPSS

Процентиль: 79%
0.01202
Низкий

Дефекты

CWE-287

Связанные уязвимости

nvd
около 18 лет назад

The tabbed browsing feature in Apple Safari 3 before Beta Update 3.0.4 on Windows, and Mac OS X 10.4 through 10.4.10, allows remote attackers to spoof HTTP authentication for other sites and possibly conduct phishing attacks by causing an authentication sheet to be displayed for a tab that is not active, which makes it appear as if it is associated with the active tab.

EPSS

Процентиль: 79%
0.01202
Низкий

Дефекты

CWE-287