Nom de la faiblesse | Source | |
---|---|---|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users. |
||
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently. |
Métriques | Score | Gravité | CVSS Vecteur | Source |
---|---|---|---|---|
V2 | 4.3 | AV:N/AC:M/Au:N/C:N/I:P/A:N | [email protected] |
Apple>>Iphone_os >> Version To (including) 1.0
Apple>>Mac_os_x >> Version *
Microsoft>>Windows_vista >> Version *
Microsoft>>Windows_xp >> Version *
Apple>>Safari >> Version 3.0
Apple>>Safari >> Version 3.0.1