Sploitus

CVE-2017-2508

3 known exploits for CVE-2017-2508

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that improperly interacts with container nodes.

Affected products
Safari, Webkit, Ios
Apple Safari
≤ 10.1
Apple Iphone Os
≤ 10.3.1
Fix
Available
CVSS 3.0
6.1 MEDIUM
EPSS
3.0% (86th percentile)
Weakness
CWE-79
NVD status
Modified
Published
2017-05-22
CVE-2017-2508 at NVD
Authoritative description, scoring and affected products

3 known exploits for CVE-2017-2508

Proof-of-concept code and exploit modules indexed by Sploitus