ID

VAR-200708-0317


CVE

CVE-2007-4431


TITLE

Apple Safari Vulnerabilities in which the same origin policy involving access to the external domain from the local zone is bypassed

Trust: 0.8

sources: JVNDB: JVNDB-2007-002523

DESCRIPTION

Cross-domain vulnerability in Apple Safari for Windows 3.0.3 and earlier allows remote attackers to bypass the Same Origin Policy, with access from local zones to external domains, via a certain body.innerHTML property value, aka "classic JavaScript frame hijacking.". Apple Safari is susceptible to a vulnerability that allows attacker to violate the same-origin policy. This issue occurs because the application fails to properly enforce the same-origin policy for JavaScript remote data access. An attacker may create a malicious webpage that can access the properties of another domain. This may lead allow the attacker to obtain sensitive information or launch other attacks against a user of the browser. Safari 3 beta is vulnerable to this issue. This vulnerability is also known as "classic JavaScript structure hijacking"

Trust: 1.98

sources: NVD: CVE-2007-4431 // JVNDB: JVNDB-2007-002523 // BID: 25355 // VULHUB: VHN-27793

AFFECTED PRODUCTS

vendor:applemodel:safariscope:lteversion:3.0.3

Trust: 1.0

vendor:applemodel:safariscope:lteversion:windows edition 3.0.3

Trust: 0.8

vendor:applemodel:safariscope:eqversion:3.0.3

Trust: 0.6

vendor:applemodel:safari beta for windowsscope:eqversion:3.0.3

Trust: 0.3

vendor:applemodel:safari betascope:eqversion:3.0.3

Trust: 0.3

vendor:applemodel:safari beta for windowsscope:eqversion:3.0.2

Trust: 0.3

vendor:applemodel:safari betascope:eqversion:3.0.2

Trust: 0.3

vendor:applemodel:safari beta for windowsscope:eqversion:3.0.1

Trust: 0.3

vendor:applemodel:safari betascope:eqversion:3.0.1

Trust: 0.3

vendor:applemodel:safari beta for windowsscope:eqversion:3

Trust: 0.3

vendor:applemodel:safari betascope:eqversion:3

Trust: 0.3

sources: BID: 25355 // JVNDB: JVNDB-2007-002523 // CNNVD: CNNVD-200708-327 // NVD: CVE-2007-4431

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2007-4431
value: MEDIUM

Trust: 1.0

NVD: CVE-2007-4431
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-200708-327
value: MEDIUM

Trust: 0.6

VULHUB: VHN-27793
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2007-4431
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-27793
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-27793 // JVNDB: JVNDB-2007-002523 // CNNVD: CNNVD-200708-327 // NVD: CVE-2007-4431

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2007-4431

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200708-327

TYPE

access verification error

Trust: 0.6

sources: CNNVD: CNNVD-200708-327

CONFIGURATIONS

sources: JVNDB: JVNDB-2007-002523

PATCH

title:Top Pageurl:http://www.apple.com/safari/

Trust: 0.8

sources: JVNDB: JVNDB-2007-002523

EXTERNAL IDS

db:NVDid:CVE-2007-4431

Trust: 2.8

db:BIDid:25355

Trust: 2.0

db:OSVDBid:46720

Trust: 1.7

db:JVNDBid:JVNDB-2007-002523

Trust: 0.8

db:CNNVDid:CNNVD-200708-327

Trust: 0.6

db:VULHUBid:VHN-27793

Trust: 0.1

sources: VULHUB: VHN-27793 // BID: 25355 // JVNDB: JVNDB-2007-002523 // CNNVD: CNNVD-200708-327 // NVD: CVE-2007-4431

REFERENCES

url:http://www.0x000000.com/index.php?i=420

Trust: 2.0

url:http://www.thespanner.co.uk/2007/08/17/safari-beta-zero-day/

Trust: 2.0

url:http://www.securityfocus.com/bid/25355

Trust: 1.7

url:http://osvdb.org/46720

Trust: 1.7

url:http://sla.ckers.org/forum/read.php?3%2c14151

Trust: 1.0

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2007-4431

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2007-4431

Trust: 0.8

url:http://sla.ckers.org/forum/read.php?3,14151

Trust: 0.7

url:http://www.apple.com/safari/

Trust: 0.3

sources: VULHUB: VHN-27793 // BID: 25355 // JVNDB: JVNDB-2007-002523 // CNNVD: CNNVD-200708-327 // NVD: CVE-2007-4431

CREDITS

Gareth Heyes discovered this issue.

Trust: 0.9

sources: BID: 25355 // CNNVD: CNNVD-200708-327

SOURCES

db:VULHUBid:VHN-27793
db:BIDid:25355
db:JVNDBid:JVNDB-2007-002523
db:CNNVDid:CNNVD-200708-327
db:NVDid:CVE-2007-4431

LAST UPDATE DATE

2025-04-10T23:19:59.698000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-27793date:2008-11-15T00:00:00
db:BIDid:25355date:2015-05-07T17:35:00
db:JVNDBid:JVNDB-2007-002523date:2012-06-26T00:00:00
db:CNNVDid:CNNVD-200708-327date:2007-08-22T00:00:00
db:NVDid:CVE-2007-4431date:2025-04-09T00:30:58.490

SOURCES RELEASE DATE

db:VULHUBid:VHN-27793date:2007-08-20T00:00:00
db:BIDid:25355date:2007-08-17T00:00:00
db:JVNDBid:JVNDB-2007-002523date:2012-06-26T00:00:00
db:CNNVDid:CNNVD-200708-327date:2007-08-20T00:00:00
db:NVDid:CVE-2007-4431date:2007-08-20T19:17:00