Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
WebKit, as used in Apple Safari before 5.0.4 and iOS before 4.3, does not properly handle redirects in conjunction with HTTP Basic Authentication, which might allow remote web servers to capture credentials by logging the Authorization HTTP header.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Apple Safari和iOS WebKit信息泄露漏洞
Vulnerability Description
WebKit是KDE、苹果(Apple)、谷歌(Google)等公司共同开发的一套开源Web浏览器引擎,目前被Apple Safari及Google Chrome等浏览器使用。 在Apple Safari 5.0.4之前版本和iOS 4.3之前版本中,WebKit没有正确处理与HTTP Basic Authentication有关的重定向。远程web服务器可以通过记录Authorization HTTP头,截获信任凭证。
CVSS Information
N/A
Vulnerability Type
N/A