Safari 1.x allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the window injection vulnerability, a different vulnerability than CVE-2004-1122.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Safari | Apple | 1.0 (including) | 1.0 (including) |
Safari | Apple | 1.1 (including) | 1.1 (including) |
Safari | Apple | 1.2 (including) | 1.2 (including) |
Safari | Apple | 1.2.1 (including) | 1.2.1 (including) |
Safari | Apple | 1.2.2 (including) | 1.2.2 (including) |
Safari | Apple | 1.2.3 (including) | 1.2.3 (including) |
Safari | Apple | beta2 (including) | beta2 (including) |