The host is installed with Apple Safari before 3.1 and is prone to a cross-site scripting vulnerability. A flaw is present in the application, which fails to handle unknown vectors related to sites that set the document.domain property or have the same document.domain. Successful exploitation could allow attackers to inject arbitrary web script or HTML.