[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Apple Safari 6.0.2 (OS X) file:// Multiple Vulnerabilities

[ 0Day-ID-20276 ]
Date add
Category
Platform
Verified
Price
 
0.008 BTC

 
500 USD
Risk
[
Security Risk Critical
]
Rel. releases
Description
The Safari web browser allows documents opened with the file:// schema to use JavaScript in a way that can be used for malicious purposes, such as stealing information about the target user from websites such as social networks, modifying the contents of a window to other websites but keeping the original website address on the address bar, or even reading files from the local system and sending them to a server controlled by the attacker. Remote exploitation is possible, since a HTML document can be opened by Safari with the file:// schema even if it is on a remote system, such as a FTP server.
Vendor
http://www.apple.com/
Tested on
Safari 6.0.2 (8536.26.17) on Mac OS X 10.8.2
Tags
apple   safari   osx   browser   file  
Prooves Information
Video proof
Other Information
Abuses
0
Comments
0
Views
14 484
We DO NOT use Telegram or any messengers / social networks! We DO NOT use Telegram or any messengers / social networks! Please, beware of scammers!
Please login or register to buy exploit.
OR
Buy incognito
0
0
Verified by 0day Admin
Verified by 0day Admin
This material is checked by Administration and absolutely workable.
Learn more about    GOLD:
0day.today Gold is the currency of 0day.today project and is denoted on this site as such image: . It used for paying for the services, buying exploits, earning money, etc
We accept:
BitCoin (BTC)
You can pay us via BTC
LiteCoin (LTC)
You can pay us via LTC
Ethereum (ETH)
You can pay us via ETH

Author
BL
29
Exploits
1
Readers
2
[ Comments: 0 ]
Terms of use of comments:
  • Users are forbidden to exchange personal contact details
  • Haggle on other sites\projects is forbidden
  • Reselling is forbidden
Punishment: permanent block of user account with all Gold.

Login or register to leave comments