CVE-2008-3170

Description

Apple Safari allows web sites to set cookies for country-specific top-level domains, such as co.uk and com.au, which could allow remote attackers to perform a session fixation attack and hijack a users HTTP session, aka Cross-Site Cooking, a related issue to CVE-2004-0746, CVE-2004-0866, and CVE-2004-0867.

Risk Information

Base Score
7.1
MODERATE
Vector
AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N
EPSS Score
Exploitation Probability
1.834

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities affected in Apple Safari 3.1.1Windows
Multiple Vulnerabilities are affected in Apple Safari 2.3Windows
Multiple Vulnerabilities are affected in Apple Safari for MAC 26.1Mac

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-613034Apple Safari for MAC (MacOS Sequoia) (26.2)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234