cbcvebase.
CVE-2009-0143
published 2009-03-14

CVE-2009-0143: Apple iTunes before 8.1 does not properly inform the user about the origin of an authentication request, which makes it easier for remote podcast servers to…

PriorityP424medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
1.87%
77.0th percentile
Apple iTunes before 8.1 does not properly inform the user about the origin of an authentication request, which makes it easier for remote podcast servers to trick a user into providing a username and password when subscribing to a crafted podcast.

Affected

1 ranges
VendorProductVersion rangeFixed in
appleitunes< 8.18.1
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.