Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Apple Safari Beta 3.0.1 for Windows allows remote attackers to execute arbitrary commands via shell metacharacters in a URI in the SRC of an IFRAME, as demonstrated using a gopher URI.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Apple Safari 协议处理命令注入漏洞
Vulnerability Description
Apple Safari是苹果家族操作系统所使用的WEB浏览器。 Safari在处理URL参数时存在漏洞,远程攻击者可能利用此漏洞控制用户机器。 Windows平台上的URL协议处理器在运行时会以特定的命令行参数执行进程。Windows平台上的Safari没有对这些参数执行正确的输入验证,因此攻击者可以绕过预期的限制注入命令。典型的URL请求,如myprotocol://someserver.com/someargument,会被转换成以下的命令行重组: "C:\Program Files\My Appl
CVSS Information
N/A
Vulnerability Type
N/A