Apple Safari 1.0 through 1.1 on Mac OS X 10.3.1 and Mac OS X 10.2.8 allows remote attackers to steal user cookies from another domain via a link with a hex-encoded null character (%00) followed by the target domain.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Safari | Apple | 1.0 (including) | 1.0 (including) |
| Safari | Apple | 1.1 (including) | 1.1 (including) |