[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

OPTIONS Request in WebKit in Apple Safari Cross-Site Request Forgery (CSRF) Vulnerability.

ID: oval:org.mitre.oval:def:6516Date: (C)2009-11-17   (M)2022-10-10
Class: VULNERABILITYFamily: windows




The implementation of Cross-Origin Resource Sharing (CORS) in WebKit, as used in Apple Safari before 4.0.4 and Google Chrome before 3.0.195.33, includes certain custom HTTP headers in the OPTIONS request during cross-origin operations with preflight, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via a crafted web page.

Platform:
Microsoft Windows 7
Microsoft Windows 8
Microsoft Windows 8.1
Microsoft Windows Server 2012 R2
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2012
Microsoft Windows Vista
Microsoft Windows XP
Microsoft Windows Server 2008 R2
Product:
Apple Safari
Reference:
CVE-2009-2816
CVE    1
CVE-2009-2816
CPE    60
cpe:/a:apple:safari:4.0:beta
cpe:/a:apple:safari:1.0.0b1
cpe:/a:apple:safari:1.0.0b2
cpe:/a:apple:safari:3.0.2b
...

© SecPod Technologies