The "Save for Web" selection in QuickTime Player in Apple Mac OS X through 10.6.8 exports HTML documents that contain an http link to a script file, which allows man-in-the-middle attackers to conduct cross-site scripting (XSS) attacks by spoofing the http server during local viewing of an exported document.
CVSS Details
- CVSS 3.1 Base Score: 4.7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Apache | — | Apply OS X security update 2011-006Upgrade macOS to the latest version | Aug 28, 2015 | Oct 14, 2011 |
| Apple Osx Quicktime | — | Apply OS X security update 2011-006 | Dec 16, 2011 | Oct 14, 2011 |
| Quicktime | — | Upgrade to Apple QuickTime version 7.7.1 | Oct 27, 2011 | Oct 14, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub