Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The page-loading implementation in WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and 8.x before 8.0.6, does not properly handle the rel attribute in an A element, which allows remote attackers to bypass the Same Origin Policy for a link's target, and spoof the user interface, via a crafted web site.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Apple Safari WebKit 安全漏洞
Vulnerability Description
Apple Safari是美国苹果(Apple)公司的一款Web浏览器,是Mac OS X和iOS操作系统附带的默认浏览器。WebKit是KDE、苹果(Apple)、谷歌(Google)等公司共同开发的一套开源Web浏览器引擎,目前被Apple Safari及Google Chrome等浏览器使用。 Apple Safari中使用的WebKit的页面加载实现过程中存在安全漏洞,该漏洞源于程序没有正确处理A元素中的rel属性。远程攻击者可借助特制的Web站点利用该漏洞绕过链接目标的同源策略,欺骗用户界面。以
CVSS Information
N/A
Vulnerability Type
N/A