Sploitus

CVE-2017-2528

4 known exploits for CVE-2017-2528

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that improperly interacts with cached frames.

Affected products
Safari, Webkit, Ios
Apple Safari
≤ 10.1
Apple Iphone Os
≤ 10.3.1
Fix
Available
CVSS 3.0
6.1 MEDIUM
EPSS
2.0% (79th percentile)
Weakness
CWE-79
NVD status
Modified
Published
2017-05-22
CVE-2017-2528 at NVD
Authoritative description, scoring and affected products

4 known exploits for CVE-2017-2528

Proof-of-concept code and exploit modules indexed by Sploitus