CVE-2009-1688 — Cross-site Scripting in Apple Safari
Severity
4.3MEDIUMNVD
EPSS
0.6%
top 29.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 10
Latest updateMay 2
Description
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject arbitrary web script or HTML via vectors related to determining a security context through an approach that is not the "HTML 5 standard method."
CVSS vector
AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9
Affected Packages1 packages
Patches
🔴Vulnerability Details
1GHSA▶
GHSA-xqv5-q33j-xfvp: Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4↗2022-05-02