Apple Safari Beta 3.0.1 for Windows allows remote attackers to execute arbitrary commands via shell metacharacters in a URI in the SRC of an IFRAME, as demonstrated using a gopher URI.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Safari | Apple | * | * |
Safari | Apple | 2.0 (including) | 2.0 (including) |
Safari | Apple | 2.0.1 (including) | 2.0.1 (including) |
Safari | Apple | 2.0.2 (including) | 2.0.2 (including) |
Safari | Apple | 2.0.3 (including) | 2.0.3 (including) |
Safari | Apple | 2.0.4 (including) | 2.0.4 (including) |
Safari | Apple | 3.0 (including) | 3.0 (including) |
Safari | Apple | 3.0.1 (including) | 3.0.1 (including) |