The host is installed with Apple Safari before 3.1 and is prone to a cross site scripting vulnerability. A flaw is present in the application, which fails to properly handle the history object. Successful exploitation allows remote attackers to inject arbitrary JavaScript.