Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 6.0 allows remote attackers to inject arbitrary web script or HTML by leveraging improper URL canonicalization during the handling of the location.href property.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2012-3642 | Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 6.0 allows remote attackers to inject arbitrary web script or HTML by leveraging improper URL canonicalization during the handling of the location.href property. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: apple
Published:
Updated: 2024-08-06T20:13:51.658Z
Reserved: 2012-06-19T00:00:00
Link: CVE-2012-3695
No data.
Status : Deferred
Published: 2012-07-25T19:55:06.210
Modified: 2025-04-11T00:51:21.963
Link: CVE-2012-3695
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD