CVE Vulnerabilities

CVE-2008-1999

Published: Apr 28, 2008 | Modified: Oct 11, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Apple Safari 3.1.1 allows remote attackers to spoof the address bar by placing many invisible characters in the userinfo subcomponent of the authority component of the URL (aka the user field), as demonstrated by %E3%80%80 sequences.

Affected Software

Name Vendor Start Version End Version
Safari Apple 3.1.1 (including) 3.1.1 (including)

References