VulnerabilityModified
CVE-2011-0217
Apple Safari before 5.0.6 provides AutoFill information to scripts that execute before HTML form submission, which allows remote attackers to obtain Address Book information via a crafted form, as demonstrated by a form that includes non-visible fields.
MEDIUM 4.3EPSS 0.97%
Does this matter?
Lower severity and a low EPSS score (0.97%). Track it; it rarely justifies an emergency change on its own.
Description
Apple Safari before 5.0.6 provides AutoFill information to scripts that execute before HTML form submission, which allows remote attackers to obtain Address Book information via a crafted form, as demonstrated by a form that includes non-visible fields.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 0.97% probability · 60th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- apple/safari
- Source
- product-security@apple.com
References
- http://lists.apple.com/archives/security-announce/2011//Jul/msg00002.htmlPatch, Vendor Advisory
- http://support.apple.com/kb/HT4808Vendor Advisory
- http://lists.apple.com/archives/security-announce/2011//Jul/msg00002.htmlPatch, Vendor Advisory
- http://support.apple.com/kb/HT4808Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.