Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The "Save for Web" selection in QuickTime Player in Apple Mac OS X through 10.6.8 exports HTML documents that contain an http link to a script file, which allows man-in-the-middle attackers to conduct cross-site scripting (XSS) attacks by spoofing the http server during local viewing of an exported document.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Apple Mac OS ‘QuickTime Player’ 跨站脚本攻击漏洞
Vulnerability Description
Apple Mac OS X是美国苹果(Apple)公司为Mac计算机所开发的一套专用操作系统。 Apple Mac OS X至10.6.8版本中的QuickTime Player中存在跨站脚本攻击漏洞。由于"Save for Web"选项输出包含到脚本文件http连接的HTML文档,中间人攻击者可通过本地浏览输出文档时哄骗http服务器,执行跨站脚本攻击。
CVSS Information
N/A
Vulnerability Type
N/A