CVE Database
/

CVE-2007-4424

Back to search

CVE-2007-4424

Published: Aug 18, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

Apple Safari for Windows 3.0.3 and earlier does not prompt the user before downloading a file, which allows remote attackers to download arbitrary files to the desktop of a client system via certain HTML, as demonstrated by a filename in the DATA attribute of an OBJECT element. NOTE: it could be argued that this is not a vulnerability because a dangerous file is not actually launched, but as of 2007, it is generally accepted that web browsers should prompt users before saving dangerous content.

VendorProductVersions

n/a

n/a

affected
n/a

References

3022
third-party-advisory
x_refsource_SREASON
1018575
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now