The host is installed with Apple Safari before 4.1 or 5.0 and is prone to a cross site scripting vulnerability. A flaw is present in the application, which fails to handle vectors involving HTML document fragments. Successful exploitation could allow attackers to inject arbitrary web script or HMTL.