CVE-2009-1700
The XSLT implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle redirects, which allows remote attackers to read XML content from arbitrary web pages via a crafted document.
- Affected products
- Safari, Webkit, Ios, Iphone Os For Ipod Touch
- Apple Safari
- ≤ 3.2.2, 2.0, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 3.0, 3.0.0, 3.0.0b, 3.0.1, 3.0.1b, 3.0.2, 3.0.2b, 3.0.3, 3.0.3b, 3.0.4, 3.0.4b, 3.1.0, 3.1.0b, 3.1.1, 3.1.2, 3.2.0, 3.2.1
- Fix
- Available
- CVSS 2.0
- 4.3 MEDIUM
- EPSS
- 2.6% (84th percentile)
- Weakness
- CWE-200
- NVD status
- Modified
- Published
- 2009-06-10
CVE-2009-1700 at NVD
1 known exploit for CVE-2009-1700
Proof-of-concept code and exploit modules indexed by Sploitus