CVE-2011-0167

MEDIUM

Description

The windows functionality in WebKit in Apple Safari before 5.0.4 allows remote attackers to bypass the Same Origin Policy, and force the upload of arbitrary local files from a client computer, via a crafted web site.

References

http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html

http://support.apple.com/kb/HT4566

http://www.securityfocus.com/bid/46816

http://www.securitytracker.com/id?1025183

Details

Source: MITRE

Published: 2011-03-11

Updated: 2011-03-31

Type: CWE-264

Risk Information

CVSS v2.0

Base Score: 4.3

Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Impact Score: 2.9

Exploitability Score: 8.6

Severity: MEDIUM