CVE Database
/

CVE-2009-3016

Back to search

CVE-2009-3016

Published: Aug 31, 2009

Modified: Aug 7, 2024

PUBLISHED

Description

Apple Safari 4.0.3 does not properly block javascript: and data: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header that contains a javascript: URI, (2) entering a javascript: URI when specifying the content of a Refresh header, (3) injecting a Refresh header that contains JavaScript sequences in a data:text/html URI, or (4) entering a data:text/html URI with JavaScript sequences when specifying the content of a Refresh header.

VendorProductVersions

n/a

n/a

affected
n/a

References

oval:org.mitre.oval:def:6475
vdb-entry
signature
x_refsource_OVAL
safari-javascript-xss(52992)
vdb-entry
x_refsource_XF

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now