Sploitus

CVE-2009-1699

3 known exploits for CVE-2009-1699

The XSL stylesheet implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle XML external entities, which allows remote attackers to read arbitrary files via a crafted DTD, as demonstrated by a file:///etc/passwd URL in an entity declaration, related to an "XXE attack."

Apple Safari
< 4.0
Apple Iphone Os
≤ 2.2.1
CVSS 3.1
7.5 HIGH
EPSS
29.1% (98th percentile)
Weakness
CWE-611
NVD status
Modified
Published
2009-06-10
CVE-2009-1699 at NVD
Authoritative description, scoring and affected products

3 known exploits for CVE-2009-1699

Proof-of-concept code and exploit modules indexed by Sploitus