Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The HTML5 drag and drop functionality in WebKit in Apple Safari before 5.0.4 allows user-assisted remote attackers to bypass the Same Origin Policy and obtain sensitive information via vectors related to the dragging of content. NOTE: this might overlap CVE-2011-0778.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Apple Safari WebKit HTML5拖放功能同源策略绕过和敏感信息泄露漏洞
Vulnerability Description
WebKit是KDE、苹果(Apple)、谷歌(Google)等公司共同开发的一套开源Web浏览器引擎,目前被Apple Safari及Google Chrome等浏览器使用。 Apple Safari 5.0.4之前版本中的WebKit中的HTML5拖放功能中存在漏洞。用户协助的远程攻击者可以借助与内容牵引有关的向量,绕过同源策略,并获得敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A