CVE-2009-2200

Publication date

2009-08-12 19:00:00

Family

mitre

State

PUBLISHED

Description

WebKit in Apple Safari before 4.0.3 does not properly restrict the URL scheme of the pluginspage attribute of an EMBED element, which allows user-assisted remote attackers to launch arbitrary file: URLs and obtain sensitive information via a crafted HTML document.