WebKit, as used in Apple Safari before 5.0.4 and iOS before 4.3, does not properly handle the Attr.style accessor, which allows remote attackers to bypass the Same Origin Policy and inject Cascading Style Sheets (CSS) token sequences via a crafted web site.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: apple
Published: 2011-03-11T22:00:00
Updated: 2024-08-06T21:43:15.359Z
Reserved: 2010-12-23T00:00:00
Link: CVE-2011-0161
Vulnrichment
No data.
NVD
Status : Modified
Published: 2011-03-11T22:55:02.947
Modified: 2024-11-21T01:23:26.947
Link: CVE-2011-0161
Redhat
No data.